Nexera Hack
What happened
On August 7, 2024, stolen management credentials let attackers take control of Nexera Fundrs contracts. Nexera reported 47.24 million NXRA removed, of which 14.75 million were sold for approximately $449,000 before the remaining 32.5 million were disabled.
Compromised contract-management credentials enabled ownership takeover and unauthorized token withdrawals.
Case & protocol details
How it happened
- Malware exposed credentials used to manage Fundrs contracts.
- Attackers transferred ownership of affected Ethereum contracts and withdrew NXRA.
- They sold tokens on Uniswap.
- Nexera paused NXRA and zeroed the remaining attacker-controlled balance.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.