A 22-year-old Canadian hacker, Andean Medjedovic, is currently on the run after allegedly exploiting a flaw in KyberSwap, a decentralized finance (DeFi) protocol, to steal $48.8 million in cryptocurrency, according to a recent indictment.
The U.S. Attorney’s Office for the Eastern District of New York claims that Medjedovic took advantage of weaknesses in KyberSwap’s code back in 2023.
Medjedovic is said to have manipulated the protocol’s liquidity pools (LPs) by borrowing vast sums of cryptocurrency, inflating prices artificially.
This led to a “glitch” in KyberSwap’s automated market maker (AMM), which allowed him to drain $48.8 million from 77 LPs spread across six public blockchains.
The hacker then allegedly attempted to blackmail KyberSwap’s developers, demanding control over the protocol and its decentralized autonomous organization (DAO) in exchange for half of the stolen assets. Medjedovic is also accused of laundering the stolen funds through various methods, including digital asset mixers and bridge protocols.
The indictment also references a previous hack in 2021, in which Medjedovic allegedly exploited Indexed Finance, siphoning off $16.5 million. He faces charges of wire fraud, computer hacking, and attempted extortion, as revealed in a Brooklyn federal court filing.
An extensive international cybercrime network has been brought down after law enforcement seized 145 domains linked to BidenCash, a notorious online marketplace that thrived on trading stolen credit card data and compromised digital identities.
Hackers in the crypto world are changing course, moving away from exploiting smart contracts and turning their focus toward tricking users directly.
Coinbase is now facing mounting scrutiny after it allegedly sat on a serious data breach for over four months, exposing the personal information of nearly 70,000 users before taking action.
A major security lapse has rocked Taiwan-based crypto exchange BitoPro, which quietly suffered an $11.5 million hack earlier in May but failed to alert users for weeks.