According to Nexus Mutual's disclosure, the funds were disbursed at UTC on Monday morning by compromising Karp's personal computer. The hacker allegedly managed to install a corrupted version of MetaMask that fooled Karp into signing a transaction that diverted all of its NXM tokens to an attacker-controlled address.
The loot amounts to 370,000 NXM, worth $8.2 million in press time. The hacker has already started exchanging the tokens to Ether (ETH), with a gross amount of more than $200,000 worth of ETH 354.
According to Nexus Mutual, Karp used a hardware wallet. The intruder, though, circumvented the defense by swapping the legal transaction with his own. Some hardware wallets can have security against these forms of attacks by requesting clarification on the system itself, where the monitor should be secured against this kind of tampering.
The intruder was a part of the mutual party, having passed the check of your client 11 days before. However, the perpetrator was not thoroughly known, with inquiries already ongoing. The perpetrator wanted to be a confirmed member of the mutual in order to collect NXM tokens, while the Nexus Mutual Group Manager told Cointelegraph that they were "working on the assumption that [the hacker] could have committed identity fraud."
The NXM token has fallen 17 percent since the attack happened, while the protocol itself has not been impacted. However, the compromised NXM in the hack corresponds to around 6 per cent of all the tokens in circulation, which may give rise to a major downward market pressure.
Karp later complemented the intruder for executing a "very nice trick." He proposed a $300,000 reward and lowered all charges in exchange for returning the tokens, reasoning that the hacker might have difficulty translating the NXM into more liquid types of currency.