Register and share your invite link to earn from video plays and referrals.

Nexus Mutual
@NexusMutual
The first crypto insurance alternative: covering crypto since 2019 @NexusMutualDAO
163 Following    41.4K Followers
Solana, You're Covered Nexus Mutual's first non-EVM listings are live: • @kamino • @Raydium • @orca_so • @JupiterExchange We've been privately underwriting @solana risk for institutional funds. Today that protection goes public, and it reaches close to 90% of Solana lending. Learn more here:
Show more
Depositors in KPK Vaults can now add opt-in cover, underwritten by @NexusMutual and arranged through @OpenCover. Here’s how it works👇
It's great when your friends work together 🤝 Awesome to see this integration between @kpk_io and @OpenCover! Explore the integrated vault and cover options below
Breaking ⚡ Protection is now integrated directly into the @kpk_io experience. KPK, a tier 1 @Morpho curator for onchain capital allocators, fintechs, and integrators, now gives depositors access to Covered Vaults, distributed by @OpenCover and underwritten by @NexusMutual. ↓
Show more
The Onchain Security Roundup tracked 1 material incident last week with over $7.9M in losses Coinsbuy: $7.9M-$8.07M. The crypto payment processor's hot TRON and Ethereum wallets were drained on August 9th. At this time, it’s unclear how the attackers got in, but some have theorized the theft was due to compromised private keys or a vulnerability in how Coinsbuy managed its multi-chain wallet infrastructure. Once the attack was detected, Coinsbuy paused deposits and withdrawals. They have since restored services and refilled the affected wallets. With the help of the ChangeNOW exchange, a six-figure portion of stolen funds was also frozen. For teams holding or processing onchain capital, this is a reminder that the loss path is not always a contract bug. Hot-wallet controls, signer access, operational response, and exchange or off-ramp dependencies can matter as much as protocol code. Nexus Mutual works with builders to assess these risks and more. If you’re looking for expert help in protecting your protocol and its users, get in touch with us. You’re Covered with Nexus Mutual
Show more
Publicly standing behind each claims decision is a very high level of accountability. All our large clients look at Nexus' claims history in their due diligence.
Full transparency around our claims is at the heart of what we do Our Chief Legal Officer @AniaWiktoria7 shares why with @gunnercooke's Kathryn Dodds
I'm trading the Alps for the Tetons for my first ever visit to Jackson Hole (had this on my ski bucket list but for now it's going to be a summer scouting trip) Excited to be attending the @SALTConference Wyoming Blockchain Symposium to engage with industry leaders on the future direction of digital asset markets - if I can make sure not to get too distracted by all the adventure sports on offer: running & mountain bike trails, white water rafting, via ferrata and paragliding; maybe I'll make some new friends that are both crypto and mountain lovers! Also pumped to see Kraken is the presenting sponsor, hope to catch up with some old friends and colleagues from my time there, the institutional platform has really grown under @DavidLRipley's leadership 🐙 At Nexus Mutual we're seeing a significant pick up in institutional interest for bespoke coverage against crypto-idiosyncratic risk. Two clear forces combining to act as carrot & stick: * first, the motivation from neobanks and fintechs looking to stand out from the crowd with a sophisticated offering when embedding DeFi in their earn offerings with FDIC-style coverage to boost consumer confidence * secondly the increased awareness and concern after high-profile exploits earlier this year, e.g. KelpDAO's rsETH impact on Aave, showing composability is one of DeFi's superpowers but also a potential Achilles' heel if risk is not properly mapped and mitigated. Institutional adoption isn't about eye-popping yields but properly managed risk-adjusted yield that is sticky and grows over the long term, a boon to users and a prize for proactive teams to get ahead of the competition. If you're attending and would like to know how we can help your protocol, fund or digital asset platform please feel free to drop me a message. See y'all in Wyoming! 🏔️🤠🏃🚵‍♂️
Show more
Who is getting ready to head out to Singapore? Our team will be in town, co-hosting Proof of Liquidity at Token2049 🤝 Sign up below!
Proof of Liquidity returns for @kbwofficial and @token2049. Invite-only capital summits hosted by @yield_network Read more below 🧵
A new version of the KPK App is live! ☑️ Deposit into and withdraw from any KPK curated Vault across supported protocols and chains ☑️ Embedded 1-click @NexusMutual cover, directly in the app Explore it:
Show more
This is a great read from @stablewatchHQ - a deep dive on the state of protection for onchain yield 📄 What can we learn from TradFi, what is the protection like today, and where is it going tomorrow? Dig in below!
Show more
Important Nexus Mutual governance proposal now live on our forum🌿
The Onchain Security Roundup tracked three incidents last week with $122M+ in reported losses Coldcard / Coinkite: ~$114M. A five-year-old firmware defect in Coldcard hardware wallets routed seed generation through a weak software randomiser (instead of the hardware RNG), allowing an attacker to reconstruct victims' private keys entirely offline and sweep their bitcoin. There have been 3 confirmed waves of losses with a potential 4th one ongoing. Coinkite published an advisory on July 30 and shipped emergency firmware on July 31, but installing it doesn't repair a previously generated seed. CryptoDAO PRO (BNB Chain): ~$7.56M–$8.2M. The function that pays out PRO rewards was open for anyone to call, with no permission check and no limits. The attacker called it repeatedly, dumping 2.8M PRO into PancakeSwap and driving the price down 32%. @HypernativeLabs identifies the fault with CryptoDAO's own distributor contract rather than PancakeSwap. LULA (BNB Chain): ~$578.1K. LULA's token contract had a privileged function that could pull tokens out of its own PancakeSwap trading pool, skipping the usual transfer checks, and then tell the pool to treat the reduced balance as correct. The attacker staged helper contracts 12 days earlier, then used a $237M flash loan to load the pool with USDT, drained the LULA side until each remaining token looked enormously valuable, and sold a small amount back at the skewed rate. Onchain risk expands beyond smart contracts to firmware and signer design around the protocol layer Key generation, privileged token mechanics, and operational dependencies can all turn into loss vectors Evaluating all of the different risks your capital is exposed to can be a difficult task, but Nexus Mutual is here to help You’re Covered with Nexus Mutual
Show more
One incorrectly priced share of SK Hynix triggered $57 million in liquidations on @HyperliquidX At the Korean pre-market open on July 28th, an order error on NXT executed a single share around 30% below the previous close Trade XYZ's oracle read that print as the reference price for the xyz:SKHYNIX perpetual market, and seven seconds later the liquidations began 960 long accounts were closed out for $17.3 million in realized losses. The oracle recovered within two minutes, but the liquidations were final Nothing was stolen and no contract was exploited It was an oracle configuration problem, due to no outlier rejection, trade-size weighting, or sanity check against the prior close Would this have been a covered event? Yes. The Hyperliquid Core Protocol Cover Annex names HIP-3 Trade[XYZ] Perpetual Markets, and Oracle Failure is a Covered Event under Nexus Mutual Protocol Cover Trade XYZ said it will reimburse eligible losses as a "one-time discretionary decision" With the speed that DeFi moves at, small errors can trigger large losses within seconds That’s why thousands of investors, protocols and funds have trusted Nexus Mutual to protect their digital assets against the unexpected
Show more
One of the challenges in DeFi risk is how everything can be interconnected @HughKarp talks risk with @gunnercooke's Kathryn Dodds
Last week had over $53 million in onchain losses, with 10 major incidents spanning key management, signer/validator control, upgrade authority, and more AFX (Anti-Fragile Exchange): $24.15M USDC. AFX is a Layer 1 chain running a perpetuals exchange with an onchain orderbook. Compromised validator hot keys reportedly met the quorum with enough signatures to clear the threshold. AFX suspended the bridge and said trading infrastructure and mainnet were untouched; a 70% white-hat offer went unanswered. Triple-A: estimated $9.7M to $11.8M. Triple-A is a Singapore payments processor that lets merchants accept crypto and get paid in fiat. Attackers took control of operational and treasury wallets across at least four chains. Triple-A says client funds weren't touched, and the Singapore Police Force is involved. VerusCoin Ethereum Bridge: $7.54M. VerusCoin is a blockchain that lets people launch their own interoperable chains. This is the bridge’s second loss in two months, after the attacker abused submitImports to trigger Ethereum-side payouts unbacked on the Verus source chain. @blockaid_ calls it the same entry point and bug class as the $11.58M May loss. Wanchain Cardano-BNB Bridge / NIGHT: $9M to $13M (depending on NIGHT's price, 515.2M taken in nine minutes). Wanchain operates cross-chain bridges. NIGHT is the token of Midnight, a privacy sidechain on Cardano. BlockSec's early read blames non-injective signed-message encoding in the Cardano-side TreasuryCheck validator, which let an approval for ~3,110 NIGHT on BNB Chain be reused to pull 203M. Wanchain took the bridge offline and acknowledged unauthorised withdrawals, the Midnight Foundation called it contained, and exchanges added precautions. B² Network B2 staking: $3.86M (~$3.01M to $3.11M realised after ~$850K of slippage). B² Network is a Bitcoin Layer 2 and a staking service on BNB Chain. The draining address had held the staking contract's upgrade authority since 2025 and only lost it after the transfer, so this was likely a compromised or insider key rather than a seizure, though B² hasn't disclosed which. B² suspended staking, promised full compensation, and offered the hacker a white-hat bounty. WEMIX: $5.22M (only ~$724K realised as the token collapsed from $1 to ~$0.0008). The attacker compromised owner authority on a WEMIX$-related contract (WEMIX is the blockchain arm of Korean game publisher Wemade), and minted 5.2M tokens outside DIOS, the stabiliser that only mints against incoming USDC, so the new supply had no reserve behind it. WEMIX suspended bridges, paused the WEMIX$ Module and PNIX DEX, withdrew foundation liquidity, requested exchange and issuer freezes, and has a contract-wide audit underway. 42DAO / Balance Protocol: $914K (plus ~$3.5M of nominal BLC erased as the token fell from $0.9954 to ~$0.0014). 42DAO is a MakerDAO fork on BNB Chain, critically missing the original’s Oracle Security Module. The attacker manipulated the BTCB feed through the Spotter/VAT liquidation path, which lacked TWAP, bounds, floor, drawdown and delay controls. Lien Finance: $542K USDC. An attacker exploited this options protocol via a logic exploit that allowed for price manipulation in their OTC pools. SlowMist blames exchangeEquivalentBonds in BondMakerCollateralizedEth, which lacked multiset integrity checks and minted BondTokens without consuming collateral, while Defimon and ExVul trace the drain through GeneralizedDotc OTC pools. These are the original Lien BondMaker contracts, and the bug class matches the September 2020 whitehat rescue of ~$10M. Garden Finance: $450K USDT across Ethereum, Base, Arbitrum and BNB Chain. Garden Finance is a Bitcoin bridge where solvers compete to fill cross-chain swaps. The bridge suffered an exploit after an offchain database breach let the solver release funds for unfunded swaps, its second such compromise in nine months after a ~$11M loss. Garden took the app offline, said nobody lost funds, and is investigating with zeroShadow, Quantstamp and Blockaid. Guru-fund Lotus deployments: $96K to $101K (~$61.5K realised after slippage). The fund management protocol suffered a loss after an attacker exploited a legacy, never-verified P2P adapter that was left enabled in the protocol registry and could grant arbitrary token allowances through the delegatecall function during normal deposits. The Guru-fund team paused the protocol and announced the protocol will be winding down in the wake of this hack. With the variety of attack vectors and pace of exploits, it’s clear that attackers are constantly looking for any way in. Whether you’re a protocol, investor, or fund looking for protection against these risks and more, get in touch with our team today. You’re Covered with Nexus Mutual
Show more
By popular allocator request, two new Covered Vaults are now live. @maplefinance Syrup USDC and USDT, now with integrated protection against covered technical and economic onchain risks ⤵️
Show more
Real-world assets have grown 10x over the last few years to a market cap of nearly $30 billion This makes tokenized stocks, treasuries and commodities a fixture in DeFi rather than a fad However, it all rests on getting a real-world price onchain accurately, and some recent losses in the space have shown that can be a risky proposition Whether it’s due to oracle failure, manipulation, misconfiguration, or a smart contract exploit, every link in the pricing chain is a potential flaw What are the real risks behind RWAs, and how can you manage it? Check out our blog to find out!
Show more
Risk adjusted yield is the way to go 🤝 If you know the @avantprotocol team, you know they don't mess around when it comes to security Explore the new Depeg Cover options below!
Another layer in the stack. @NexusMutual depeg cover is now available for: 🔹 savUSD @ 2.1% 🔹 savETH @ 2.23% 🔹 savBTC @ 2.23% Available now for holders who want an extra layer of protection.
Show more
Depeg Cover is now available for @frankencoinzchf users. Users can now add protection against defined depeg events through OpenCover. Built by OpenCover, underwritten by @NexusMutual ⤵️
Show more
The Onchain Security Roundup tracked 6 major incidents last week, with over $28.3M in reported losses As smart contract security improves, attackers are going after the underlying economic assumptions (oracles, liquidity depth, mark prices) rather than the contracts themselves Ostium: 23.75M USDC drained from its LP vault after offchain price-feed infrastructure was compromised. @blockaid_ reported that a registered PriceUpKeep forwarder and future-dated authorized oracle reports were used to create artificial trading profits to extract funds from the OLP vault. Trading remains paused, with investigation and LP recovery details pending Allbridge Core: $1.65M lost from a flash-loan-assisted manipulation of Allbridge's StableSwap-style automated market maker, where the attacker exploited the same-asset swap accounting divergence. The protocol paused and asked LPs in affected pools to withdraw while the investigation continues Cascade CLS Vault: $1.3M lost after thin-liquidity markets and manipulated mark prices triggered liquidations against the CLS vault. Trading and withdrawals remain paused BarnBridge SMART Yield cUSDC: $776K drained from a dormant protocol after a governance takeover allowed the attacker to use legacy USDC approvals DeFiTuna: $570K lost from a Solana lending-pool issue involving a highly illiquid TUNA/USDC pool, Jupiter routing, and a rounding/solvency-check flaw. DeFiTuna said the vector was identified and mitigated, with investigation and recovery ongoing Lumi Finance / Sodium Smart Accounts: approximately $270K drained after a design flaw in smart-account validation logic allowed an attacker to gain unintended token approvals These are the exact sorts of risk that Nexus Mutual can cover: oracle failures, oracle manipulation, governance takeovers, and smart contract exploits Whether you’re a protocol, investor, or fund looking for protection against the changing risks in DeFi, Nexus Mutual is there to help
Show more