There’s been another theft in the Cryptoverse – this time a ‘personal’ one, as attackers have taken more than USD 8.2m from the account of Hugh Karp, the founder of decentralized finance (DeFi) insurance protocol Nexus Mutual.
Nexus Mutual announced the news in a Twitter post today, stating that Karp’s “personal address was attacked and drained by a member of the mutual.” They stated that only this particular address was affected in “this targeted attack and there is no subsequent risk to Nexus Mutual or any members,” adding that “the mutual is not impacted; the pool of funds and all systems are safe.”
According to the transaction details, NXM 370,000 was taken, worth some 8.25m. Per CoinGecko.com, the price of the coin dropped less than 1% in the past 24 hours, and 4.7% in a week, to the current price of USD 22.3 (at 12:32 UTC).
A part of the stolen funds is already being exchanged, said the protocol.
Nexus Mutual described this as a “targeted personal attack on Hugh,” explaining further that the attacker gained remote access to Karp’s computer and modified the MetaMask extension, “tricking him into signing a different transaction which transferred funds to the attacker’s own address.” According to them, the attacker completed know-your-customer (KYC) 11 days ago but then switched membership to a new address on December 3. “Our investigation is ongoing to identify the attacker and how they operated,” they said.
Meanwhile, Karp himself described this attack as “next level stuff,” promising a high bounty and a stop to the investigation should he attacker return the funds – a move which some commenters thought may incentivize other bad players.