T
iTokenly

Nexera hack — August 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedAugust 7, 2024
Target typeToken contract
Loss$1,800,000Published estimates range $449,000 to $1,800,000Price at time of incident
Recovered$1,230,000
MethodPrivate key compromiseMalware executed on an employee's machine harvested the credentials used to administer Nexera's smart contracts. The attackers transferred ownership of the affected Ethereum contracts to themselves, blocked further upgrades and ownership reassignment, then called an administrative withdraw function to move 47.24 million NXRA out of the contracts. They subsequently accessed vesting contracts on Avalanche and transferred token balances there as well.
ChainsEthereum, Avalanche
Attributed toSuspected DPRK-linked threat actors (BeaverTail malware)Suspected
OutcomePartially recovered

What happened

Nexera, a tokenisation infrastructure project whose NXRA token and Fundrs platform ran on Ethereum, was attacked on 7 August 2024 beginning at 02:10 UTC.

According to Nexera's own post-mortem, attackers ran malicious code on an employee's machine and obtained the credentials used to manage the project's smart contracts. They then transferred ownership of the affected Ethereum contracts to themselves and blocked the team from reassigning ownership or upgrading, before calling an administrative withdraw function to move 47.24 million NXRA out of the contracts. Cyvers detected the transfers and described an address taking ownership of the proxy contract, upgrading it, then using the withdraw admin function to take all the NXRA. Nexera paused the token contract across Ethereum, Avalanche, Arbitrum and Polygon, asked exchanges to suspend trading, and reported the incident to Dutch police at 07:47 UTC the same morning. NXRA fell around 40%.

The figures are disputed and the gap is wide. Cyvers put the loss at $1.8 million, comprising 32.5 million NXRA then worth about $1.23 million plus $555,000 in USDT; earlier Cyvers reporting gave about $1.5 million. Nexera stated that the attackers sold roughly 14.75 million tokens for around $449,000 and that only about $440,000 was effectively compromised, because the team zeroed the remaining 32.5 million NXRA held in the attackers' wallets. Both the gross and net figures are recorded here.

Nexera identified the malware as BeaverTail and said the delivery methods were consistent with state-backed actors. ZachXBT linked the same attacker to earlier compromises including Concentric Finance, Serenity Shield and Reach. No charges have been reported.

Law enforcement

Nexera reported the incident to Dutch police at 07:47 UTC on 7 August 2024.

Sources

  1. NexeraPrimary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. HackreadSecondary · retrieved 2026-08-01
  4. The Cyber ExpressSecondary · retrieved 2026-08-01

Official post-mortem: https://nexera.medium.com/240807-incident-post-mortem-report-5f1f7840d4d7

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Nexera hack — August 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nexera
https://itokenly.com/hacks/nexera

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.