US prosecutors have secured what they describe as the first-ever criminal conviction for hacking a smart contract, with former security engineer Shakeeb Ahmed sentenced to three years in prison for exploiting vulnerabilities in two decentralized cryptocurrency exchanges’ smart contracts and stealing over $12 million in digital assets. According to the U.S. Attorney’s Office for the Southern District of New York, Ahmed previously pleaded guilty to one count of computer fraud tied to July 2022 attacks on an unnamed Solana-based DEX (referred to in court documents as the “Crypto Exchange”) and on Nirvana Finance, a Solana-based DeFi protocol. Prosecutors say Ahmed, then a senior security engineer at a large international tech company, used his skills in reverse engineering and smart contract auditing to identify and exploit flaws in the exchanges’ smart contracts. In the first incident, he inserted fake pricing data into a smart contract to generate millions of dollars in unearned fees that he withdrew as cryptocurrency, later attempting to negotiate to keep a portion as a supposed “bounty.” Later that month, he allegedly exploited Nirvana Finance’s smart contracts to buy its token at artificially low prices and immediately resell to the protocol at higher prices, extracting about $3.6 million and ultimately contributing to Nirvana’s shutdown after refusing to return funds when a lower bug bounty was offered. Authorities say he then laundered the proceeds using token swaps, cross-chain bridges, mixers (including Samourai Whirlpool), and overseas exchanges. In addition to the prison term, Ahmed, 34, of New York, was ordered to forfeit approximately $12.3 million in proceeds and pay more than $5 million in restitution to the two victim platforms. U.S. Attorney Damian Williams framed the case as a landmark for DeFi enforcement, emphasizing that exploiting smart contract code and labeling it an “exploit” or “bug bounty” does not shield actors from traditional computer fraud charges. For the broader crypto and DeFi ecosystem, the case underscores growing prosecutorial focus on smart contract exploits and money laundering via cross-chain tools and privacy-enhancing technologies, and signals that on-chain attacks framed by some participants as “white-hat” or “code is law” disputes may be treated as criminal hacking when pursued by law enforcement. "entities":["Shakeeb Ahmed","Nirvana Finance","United States Attorney’s Office for the Southern District of New York (SDNY)","Damian Williams","Victor Marrero","Ona T. Wang","Samourai Whirlpool","Monero","Amazon (former employer referenced)","Solana","Ethereum","Southern District of New York (SDNY)"]}'} indistinguishable from ordinary bug bounty or gray‑hat activity and that exploiting publicly visible smart contract code can still be prosecuted under existing computer fraud and money laundering statutes. "entities":["Shakeeb Ahmed","Nirvana Finance","United States Attorney’s Office for the Southern District of New York (SDNY)","Damian Williams","Victor Marrero","Ona T. Wang","Samourai Whirlpool","Monero","Amazon (as Ahmed’s former employer, per reports)","Solana","Ethereum","Crypto Exchange (unnamed decentralized exchange)"]}`

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Smart Contract

Comments