{"id":132944,"date":"2020-12-14T15:36:48","date_gmt":"2020-12-14T12:36:48","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/founder-of-defi-protocol-nexus-mutual-gets-hacked-for-8m\/"},"modified":"2020-12-14T15:36:48","modified_gmt":"2020-12-14T12:36:48","slug":"founder-of-defi-protocol-nexus-mutual-gets-hacked-for-8m","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/founder-of-defi-protocol-nexus-mutual-gets-hacked-for-8m\/","title":{"rendered":"# Founder of DeFi protocol Nexus Mutual gets hacked for $8M"},"content":{"rendered":"<p>&#8220;<strong># Founder of DeFi protocol Nexus Mutual gets hacked for $8M<br \/>\n<\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjAtMTIvODZjOTRhMGMtYWZjZi00NWVhLWE3N2MtMDhmMDFlNTE4OTEyLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-5a136f3a>\nAn unknown attacker stole $8 million from the personal wallet of Hugh Karp, the CEO of DeFi coverage platform Nexus Mutual. <\/p>\n<p>According to a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/NexusMutual\/status\/1338441873560571906?s=20\">disclosure<\/a> by Nexus Mutual, the funds were drained on Monday morning UTC by compromising Karp\u2019s personal device. The hacker reportedly managed to install a compromised version of MetaMask that tricked Karp into signing a transaction that redirected all his NXM tokens to an attacker-controlled address.<\/p>\n<p>The <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/etherscan.io\/tx\/0x4ddcc21c6de13b3cf472c8d4cdafd80593e0fc286c67ea144a76dbeddb7f3629\">loot<\/a> amounts to 370,000 NXM, worth $8.2 million as of press time. The hacker already began <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/etherscan.io\/address\/0x03e89f2e1ebcea5d94c1b530f638cea3950c2e2b#tokentxns\">converting<\/a>\u00a0the tokens to Ether (ETH), with a total balance of 354 ETH worth more than $200,000.<\/p>\n<p>According to Nexus Mutual, Karp was using a hardware wallet. However, the attacker circumvented the protection by replacing a legitimate transaction with his own. Some hardware wallets should provide protection against these types of attack by requiring a confirmation on the device itself, where the display should be protected against this form of tampering.<\/p>\n<p>The attacker was a member of the mutual, having passed know-your-client verification 11 days ago. The attacker was not fully identified though, with investigations still pending. The attacker needed to be a verified member of the mutual in order to receive NXM tokens, though a Nexus Mutual community manager told Cointelegraph that they are &#8220;working on the assumption that [the hacker] could have committed identity fraud.&#8221;<\/p>\n<p>The NXM token dropped 17% since the attack occurred, although the protocol itself was not affected. Nonetheless, the NXM stolen in the hack amounts to <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>roximately 6% of all tokens in circulation, which could pose significant downward pressure on price.<\/p>\n<p>Karp later <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/HughKarp\/status\/1338452087374553091?s=20\">complemented<\/a> the attacker for performing a &#8220;very nice trick.&#8221; He offered a $300,000 bounty and dropping all charges in exchange for returning the tokens, arguing that the hacker would have trouble in converting the NXM into more liquid forms of money.<br \/>\n<template data-name=\"subscription_form\" data-type=\"defi_newsletter\"><\/template>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/founder-of-defi-protocol-nexus-mutual-gets-hacked-for-8m\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Founder of DeFi protocol Nexus Mutual gets hacked for $8M &#8221; An unknown attacker stole $8 million from the personal wallet of Hugh Karp, the CEO of DeFi coverage platform Nexus Mutual. According to a disclosure by Nexus Mutual, the funds were drained on Monday morning UTC by compromising Karp\u2019s personal device. The hacker&#8230;<\/p>\n","protected":false},"author":1,"featured_media":132945,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/s3.cointelegraph.com\/uploads\/2020-12\/86c94a0c-afcf-45ea-a77c-08f01e518912.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74868,74882,75190,4965],"class_list":["post-132944","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-defi","tag-hacks","tag-hardware-wallet","tag-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/132944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=132944"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/132944\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/132945"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=132944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=132944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=132944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}