Share this article

CEO of DeFi Insurer Nexus Mutual Hacked for $8M in NXM Tokens

Nexus Mutual's CEO, Hugh Karp, lost the tokens after an attacker gained remote access to his computer.

Updated Sep 14, 2021, 10:42 a.m. Published Dec 14, 2020, 1:11 p.m.
Laptop user

The CEO of decentralized finance (DeFi) insurer Nexus Mutual has lost the equivalent to over $8 million in a targeted attack, the firm disclosed Monday.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

A total of 370,000 of the project's native NXM tokens were drained from Hugh Karp's address to one owned by the attacker at 09:40 am UTC, according to data source etherscan.io. The transaction cost 0.00429472 ETH, or $2.49.

Hugh Karp's personal address transaction
Hugh Karp's personal address transaction

The attacker, also a Nexus Mutual member, completed KYC (know-your-customer) 11 days ago and switched to a new address on Dec. 3, before gaining remote access to Karp's computer and modified MetaMask wallet extension, according to the company's tweets. That tricked him into signing a different transaction that transferred funds from his hardware wallet to attacker's address.

Only Karp's address has been compromised and so far Nexus Mutual and its members have remained unaffected. "The mutual is not impacted; the pool of funds and all systems are safe," according to another tweet an hour ago.

Since news of the attack broke, the price of wrapped NXM tokens has declined by over 14% to 16.66 USDT (tether) on cryptocurrency exchange Huobi.

Some of the stolen funds have been transferred via decentralized exchange aggregator 1inch.exchange. "We welcome any assistance to stop the funds, which will likely move quickly," Nexus said.

Nexus Mutual is a community-owned insurance alternative, offering protection from various risks in the DeFi ecosystem. Only members can participate in the network, buy cover and hold NXM tokens.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Why is Bitcoin Trading Lower Today?

BTC's price. (CoinDesk)

Market uncertainty persists due to internal Fed divisions and unclear future rate paths until 2026.

What to know:

  • Bitcoin and Ether prices fell following the Federal Reserve's rate cut and mixed signals about future monetary policy.
  • The Fed's decision to purchase short-term Treasury bills aims to manage liquidity, not to implement quantitative easing.
  • Market uncertainty persists due to internal Fed divisions and unclear future rate paths until 2026.