Nexus Mutual founder's personal wallet address gets attacked, funds worth more than $8 million get drained

Quick Take

  • Nexus Mutual founder Hugh Karp’s personal wallet address has just experienced an attack that resulted in a loss of more than $8 million.
  • Karp told The Block that the attacker tricked him into approving one transaction, somehow gained access to his computer, and altered his MetaMask extension.

Hugh Karp, the founder of DeFi insurance protocol Nexus Mutual, has just experienced an attack that resulted in a loss of more than $8 million.

Nexus Mutual announced the news via a Twitter post on Monday, saying that Karp's personal wallet address was attacked and drained by a member of the protocol.

The address contained 370,000 NXM (Nexus Mutual) tokens, currently worth about $8.25 million. 

Karp told The Block that the attacker tricked him into approving one transaction, somehow gained access to his computer, and altered his MetaMask extension.

"Then when I was performing an unrelated transaction, MetaMask popped up with a spoof transaction, and I subsequently approved it, thinking it was the transaction I was intending to conduct. Instead, it was transferring NXM to their wallet," said Karp.

Nexus Mutual is unaffected and nobody else is impacted, he said. "My private keys are still secure. The attacker didn't get access to them. They tricked me into signing a spoof transaction," said Karp. 

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

He characterized the attack as a "very nice trick" and "definitely next level stuff." 

Nexus Mutual said the attacker completed their know-your-customer (KYC) processes 11 days ago and then switched membership to a new address on December 3. The protocol developer added that an investigation is ongoing to identify the attacker and how they operated.

Karp asked the attacker to return funds to drop all investigations and get $300,000 in the bounty. 

Some of the stolen funds are already on the move, said Nexus Mutual, adding that some are already being exchanged using decentralized exchange aggregator 1inch.Exchange.

This is a developing story and will be updated as more details are known.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Yogita Khatri is a senior reporter at The Block, covering all things crypto. As one of the earliest team members, Yogita has played a pivotal role in breaking numerous stories, exclusives and scoops. With nearly 3,000 articles under her belt, Yogita holds the records as The Block's most-published and most-read author of all time. Prior to joining The Block, Yogita worked at crypto publication CoinDesk and The Economic Times, where she wrote on personal finance. To contact her, email: [email protected]. For her latest work, follow her on X @Yogita_Khatri5.