Nexera Hack

REPORTED LOSS $1.8M
Medium Compromised management credentials ethereum

What happened

On August 7, 2024, stolen management credentials let attackers take control of Nexera Fundrs contracts. Nexera reported 47.24 million NXRA removed, of which 14.75 million were sold for approximately $449,000 before the remaining 32.5 million were disabled.

Technical Root Cause

Compromised contract-management credentials enabled ownership takeover and unauthorized token withdrawals.

Case & protocol details

Classification Infrastructure / Credential Compromise
Protocol Type Exploit/Access control
Implementation language Solidity
Protocol Twitter/X @Nexera_Official

How it happened

  1. Malware exposed credentials used to manage Fundrs contracts.
  2. Attackers transferred ownership of affected Ethereum contracts and withdrew NXRA.
  3. They sold tokens on Uniswap.
  4. Nexera paused NXRA and zeroed the remaining attacker-controlled balance.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.