The attacker, also a Nexus Mutual member, completed KYC (know-your-customer) 11 days ago and switched to a new address on Dec. 3, before gaining remote access to Karp’s computer and modified MetaMask wallet extension, according to the company’s tweets. That tricked him into signing a different transaction that transferred funds from his hardware wallet to attacker’s address.
-
https://www.coindesk.com/ceo-of-defi-insurer-nexus-mutual-hacked-for-8m-in-nxm-tokensHow stupid can this CEO be or, should I say, how lame is that excuse?
It won't be long for the funds to be returned if they really identified the attacker assuming what was sent for KYC verification was his real data. The CEO also said that it will be difficult to cash out the hacked tokens but he still offered a $300K bounty hehe.

-
https://twitter.com/HughKarp/status/1338452087374553091An easy $300K for the "attacker" huh?