{"id":88929,"date":"2024-08-07T07:30:56","date_gmt":"2024-08-07T11:30:56","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=88929"},"modified":"2024-08-07T13:27:13","modified_gmt":"2024-08-07T17:27:13","slug":"nexera-protocol-1-5m-smart-contract-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/nexera-protocol-1-5m-smart-contract-exploit\/","title":{"rendered":"Nexera Protocol Faces $1.5M Smart Contract Exploit"},"content":{"rendered":"\n<p>A smart contract security incident has resulted in the exploitation of the Nexera protocol, resulting in the theft of $1.5 million in <a href=\"https:\/\/coinscreed.com\/staging\/vanuatu-to-pass-crypto-digital-assets-bill-in-september.html\" data-type=\"post\" data-id=\"82736\">digital assets<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"574\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA-1024x574.webp\" alt=\"\" class=\"wp-image-88951\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA-1024x574.webp 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA-300x168.webp 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA-768x430.webp 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA-860x482.webp 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA-1320x740.webp 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA.webp 1456w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Nexera Protocol Faces $1.5M Smart Contract Exploit<\/figcaption><\/figure>\n\n\n\n<p>According to an August 7 X post by Cyvers, Nexera, a decentralized finance (DeFi) protocol that sought to connect DeFi with traditional finance, was compromised for $1.5 million in Nexera (NXRA) tokens.<\/p>\n\n\n\n<p>Our system has identified a suspicious transaction that pertains to your proxy contract. An address assumed the proprietorship of your proxy contract and upgraded it. Shortly after, the address utilized the withdraw admin function to transmit the $NXRA tokens.<\/p>\n\n\n\n<p><em>\u201cOur system has detected a suspicious transaction involving your proxy contract.\u00a0An address took ownership of your proxy contract and upgraded it. Shortly after, the address used the withdraw admin function to transfer all the $NXRA tokens.\u201d<\/em><\/p>\n\n\n\n<p>Although the $1.5 million is considered a relatively minor incident, it occurred only one day after Ronin Network was exploited by a suspected <a href=\"https:\/\/coinscreed.com\/staging\/crema-hacker-returns-8-million-keeps-1-6-million-in-bounty.html\" data-type=\"post\" data-id=\"31716\">white-hat hacker<\/a>, who stole $9.8 million in Ether tokens. The hacker promptly returned all of the lost funds within a few hours.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"423\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6-1024x423.png\" alt=\"\" class=\"wp-image-88947\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6-1024x423.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6-300x124.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6-768x318.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6-860x356.png 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6-1320x546.png 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/image-6.png 1359w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Nexera exploit. Source: Cyvers<\/em><\/figcaption><\/figure>\n\n\n\n<p>The perpetrator is currently evading authorities with the stolen funds, evidence of the incident's malicious intent.<\/p>\n\n\n\n<p>According to Cyvers, the infiltrator has initiated the sale of a portion of the NXRA tokens for Ether.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cThe address is currently selling all the tokens for $ETH, and some of the funds have already been bridged to the $BNB chain. The total estimated loss is around $1.5 million.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Hackers frequently convert their stolen tokens into Ether to launder the funds through cryptocurrency mixers such as <a href=\"https:\/\/en.wikipedia.org\/wiki\/Tornado_Cash\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/Tornado_Cash\" rel=\"noreferrer noopener nofollow\">Tornado Cash<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>. This process complicates tracing the origin of the funds for cybersecurity firms.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Nexera hacker is associated with previous exploits<\/h2>\n\n\n\n<p>According to onchain data, this is not the exploiter's initial malevolent incident.<\/p>\n\n\n\n<p>ZachXBT, an onchain investigator, stated in a Telegram post on August 7 that the exploiter's addresses are also associated with previous private key compromises.<\/p>\n\n\n\n<p>&#8220;Attacker is on-chain linked to recent private key compromise incidents, including SpaceCatch, Concentric Finance, OKX DEX, Serenity Shield, Reach, and many others.&#8221;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cAttacker is connected on-chain to recent private key compromise incidents such as SpaceCatch, Concentric Finance, OKX DEX, Serenity Shield, Reach, and many more.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>The exploit transpired nearly three weeks after a hacker stole more than $230 million from WazirX, an Indian cryptocurrency exchange, in the second-largest cryptocurrency breach of 2024 thus far.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A smart contract security incident has resulted in the exploitation of the Nexera protocol, resulting in the theft of $1.5 million in digital assets. According to an August 7 X post by Cyvers, Nexera, a decentralized finance (DeFi) protocol that sought to connect DeFi with traditional finance, was compromised for $1.5 million in Nexera (NXRA) [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":88951,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[2118,21159,18914],"class_list":["post-88929","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-hacker","tag-nexera-protocol","tag-smart-contract-exploit"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/08\/NEXERA.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/88929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=88929"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/88929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/88951"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=88929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=88929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=88929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}