CryptoReal
CASE FILE — Dec 23, 2020

Inside the $8M Nexus Mutual Hack — Founder Hugh Karp on What Happened Next

Owning a hardware wallet and never exposing your private keys is not, on its own, a guarantee of safety — not if the machine you're signing from has already been compromised. That is the lesson at the center of the $8 million theft suffered by Nexus Mutual founder Hugh Karp, who agreed to an interview roughly one week after the incident to walk through what happened and what he's learned since.

Unlike cases involving reckless leverage or careless key management, this one involved a targeted attack against someone who had taken reasonable precautions. That distinction is why it's being covered differently here: with sympathy for the victim rather than the usual scorn. The details below draw on that conversation and on Karp's own published account of the incident.

01What happened

On the morning of Monday, December 14, at 9:40am UTC, Karp was manipulated into signing a single transaction he believed was claiming mining rewards. Instead, it authorized the transfer of 370,000 NXM directly to an attacker. Most of the stolen NXM has since been converted into ETH and BTC and spread across numerous wallets and exchange accounts, making recovery difficult.

02The immediate aftermath

Karp described the first three hours after realizing what had happened as by far the worst — a "gut-wrenching sick feeling," accompanied by physical shaking and weakness. Nexus Mutual's CTO, Rox, and its security lead, Anatol, stepped in early to take charge of the response and walk Karp through immediate next steps, after which the broader community joined in to help trace where the stolen funds were moving.

Looking back on the psychological toll, Karp said he's generally settled now and tends to take a long view of setbacks. He noted that NXM was trading at only around $3 before the DeFi boom took hold earlier in the year, meaning the money lost hadn't even existed for him four or five months prior — a framing he's used to stay confident that the business, like any startup navigating ups and downs, will recover.

03Not an isolated incident

Karp said his team, while tracing the movement of stolen funds, identified at least two other Nexus Mutual members who appear to have suffered comparable attacks, and that he's heard anecdotally — through separate contacts — of additional victims beyond those. He pushed back on the idea that this was such a highly targeted attack that ordinary DeFi users have nothing to worry about. While there may be some truth to that, he cautioned that a person doesn't need to be high-profile to be targeted, and warned against assuming "it's not going to happen to me."

04Why the hardware wallet didn't stop it

Sums referenced in this case file

Karp's private keys were never exposed — he was using a hardware wallet throughout. The problem, he explained, is that while a hardware device does display enough transaction detail for a user to verify what they're approving, actually interpreting that information requires real technical fluency. Straightforward transfers of well-known tokens are easy enough to check, but verifying an arbitrary smart-contract interaction is, in his view, close to impossible for most regular users. Going forward, he said he personally plans to cross-check full transaction details against independent external sources before signing anything, though he acknowledged that's not a realistic habit to expect from every user.

05How the compromise happened

Karp's account states plainly that his computer was compromised and that his MetaMask installation was altered directly on disk — not through any leak of his seed phrase or keys. At the time of the interview, a full diagnostic of the machine was still underway, so the exact infection vector wasn't confirmed, but the team believed the malware was likely served from the domain coinbene[.]team, while not ruling out another source entirely.

06Tracing the attacker

Nexus Mutual's CTO, Roxana, had a brief exchange with one of the hackers over Telegram. Separately, by tracing on-chain fund movements and working with law enforcement, the team was able to connect this attack to other victims. Karp declined to share further specifics while investigations were ongoing, saying only that the team believes they're dealing with a highly sophisticated hacking group.

07Law enforcement's involvement

Karp confirmed the team had reported the theft to UK police, who are coordinating with counterparts in other jurisdictions, and that related cases have been folded into a larger, combined investigation. Asked whether police seemed well-equipped to handle a case like this — given how rarely large crypto hacks and exploits end up before law enforcement at all — Karp said not really; police units are generally set up around smaller-scale crime such as credit card fraud, and the cross-border nature of crypto theft further slows down coordination and response.

08On insurance-related exploitation

Asked about the risk of attackers taking out insurance coverage before executing an exploit — effectively doubling their payout — Karp said he hasn't personally seen that happen yet, though he expects it eventually will. Nexus Mutual has built in a "proof of loss" requirement specifically to guard against this: claimants must demonstrate control over the account that actually suffered the loss, which limits the worst-case abuse. He noted that insurance products can be designed without that safeguard, but doing so drives up long-run costs since more claims end up getting paid out — aligning incentives properly, he argued, matters more for products meant to be sustainable over time.

09Turning the loss into something useful

The community organized a Gitcoin grant to help offset Karp's losses, and he said the proceeds are earmarked for wallet-security development rather than simply personal reimbursement. While the specifics haven't been finalized, his goal is to support progress on personal wallets that are both highly secure and genuinely usable — an area he says multiple teams are already working on, with meaningful distance still to cover. Given that his situation, while high-profile, reflects a problem affecting the wider self-custody space, he's hoping the grant becomes a catalyst for broader improvement rather than just a one-off fix.

Those interested in contributing can do so through the Gitcoin grant page. Nexus Mutual can be followed on Twitter at @NexusMutual or found on Discord.

hughnexus mutual
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.