Nexus Mutual Hack

Reported loss $8.0M
Ethereum
Tampered MetaMask interface presenting a spoofed transfer

What happened

On December 14, 2020, attackers stole 370,000 NXM, worth roughly $8 million at the time, from Nexus Mutual founder Hugh Karp's personal Ledger-connected wallet. Karp's Windows endpoint and MetaMask extension were tampered with, causing a spoofed transaction to be displayed when he attempted to claim rewards. He approved the transaction, which transferred NXM to the attacker.

Ledger private keys, Nexus Mutual smart contracts, the mutual's capital pool, and other members were not compromised.

How it happened

This was an endpoint and transaction-signing deception attack. After compromising Karp's computer and replacing or modifying the MetaMask extension, the attacker made a malicious NXM transfer appear to be a legitimate reward-claim transaction. The hardware wallet signed the transaction Karp approved, but the signed destination was attacker-controlled.

No smart-contract flaw or private-key extraction was required.

Protocol details

Classification Endpoint compromise and transaction-signing deception
Protocol Type Insurance
Implementation language Solidity
Protocol links Website @NexusMutual

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.