CryptoReal
CASE FILE — Feb 10, 2021

Armor Faces Backlash for Denying a Policyholder's $1.6 Million Nexus Mutual Claim

An insurance protocol built to protect DeFi users instead stands accused of misappropriating a policyholder's payout, in a dispute marked by shifting statements, a quietly modified smart contract, and a settlement offer its intended recipient has refused.

At the center of the controversy is Armor, a DeFi cover-staking platform, and its CEO, Azeem. Armor is accused of reneging on a $1.6 million insurance payout owed to a user known on Twitter as @kferretcrypto, after that user's staked policy token unexpectedly surged in value following last week's Yearn arbitrage exploit.

How the policy ended up staked

In September 2020, kferretcrypto purchased Nexus Mutual cover policy #1804. On the advice of Armor's Azeem, kferret later staked the token representing that policy with Armor, on the understanding that it could be unstaked and the claim filed whenever needed.

That understanding was tested when Yearn's v1 DAI vault was exploited, draining 11 million DAI. The hack meant cover #1804 had suddenly become worth 1,000 ETH in potential claims.

Armor's reversal

Rather than honoring the payout, Azeem and the rest of the Armor team argued that because the token had been staked, kferret had forfeited any right to the 1,000 ETH — and that the proceeds would instead be routed to what Armor called its "Treasury Reserve." Adding to the dispute, on-chain evidence has been cited suggesting Armor moved the staked NFT out and restaked it through its own contracts before filing the claim under its own name.

Armor has since sent a formal reply to kferret — addressed to his account alias, "x7044" — in a shared Google document. Asked for his reaction, kferret rejected the resolution outright. He said Azeem's original assurances — that stakers would keep ownership of their cover benefits and could withdraw and claim at any point during this phase of the project — were what convinced him to deposit the NFT in the first place. He said the staking contract was later altered without notice to let an administrator move his NFT to a personal wallet, something he says actually occurred, and characterized the whole affair as nothing short of the theft of $1.6 million that belongs to him.

Screenshots of private chats between kferret and the Armor team circulated showing the dispute unfold in real time. A subsequent written statement from Armor team member "Umadbruhh," together with kferret's point-by-point rebuttal, was later posted to Pastebin.

Point, counterpoint

Sums referenced in this case file

Following the leaked chats, Armor issued a further official response that appeared to soften its original position. The exchange, drawn from that response and kferret's reply to it, ran roughly as follows:

Armor noted that, the previous week, it had launched a "Coverage for Coverage Providers" product funded by the Treasury Reserve, meant to protect arNXM yield-vault depositors from losses tied to successful claims at no extra cost. kferret said he'd never even heard of this product and had never consented to his funds being redirected toward it — adding that Azeem had told him directly that, since Armor's brokerage feature ("arCore Protect") wasn't yet live, he could still claim normally and keep the benefit himself.

Armor further stated that the recovered 1,000 ETH would flow into the Treasury Reserve to buy back NXM, replenishing stakes burned in the arNXM vault and restoring its arNXM:wNXM ratio. kferret countered that he had already offered, on his own initiative, to contribute $100,000 toward covering the vault's losses — an offer he says Azeem accepted and seemed pleased with, even directing co-founder Robert to begin returning the NFT. That transfer, according to kferret, never happened; instead, hours later, Umadbruhh delivered the letter declaring that nothing the CEO says is binding.

In that letter, Umadbruhh introduced himself as an Armor co-founder responsible for protocol health and said the offered resolution followed the rules set out in Armor's technical documentation. kferret argued the documentation itself was out of step with how the product actually worked at the time, making it unreasonable to weight it over the CEO's direct, contemporaneous statements.

Armor's letter also asserted that Azeem's discussions with kferret were informal and non-binding, subject instead to the team's agreement during a governance grace period or eventual DAO approval, and that the official documentation superseded any such conversations. kferret read this as an admission that nothing the team says can be relied on, since it can be overridden at will.

Citing its own documentation — which states that staked arNFTs "do not provide coverage to the user who staked them" and are instead leased to the system in exchange for rewards or revenue share — Armor argued the arNFT had never covered kferret to begin with. kferret responded that the cited clause referred to a brokerage feature that hadn't launched, that Azeem had repeatedly and explicitly told him the opposite applied during this phase, and that no one had actually purchased coverage through Armor at that point — adding it was unclear whether Armor's DAO functioned in any meaningful sense at all.

Armor went on to claim sole stakeholder status over the decision, arguing it held all claim-submission and payout rights to a staked arNFT for as long as it remained staked, including through the seven-day cooldown following an unstake request — a window it said exists specifically so the Armor DAO can weigh cases like this one. Paying kferret, it argued, would mean a payout to someone without rights to the claim, at the cost of Armor DAO's own stake in the Yearn contract, which it called neither ethical nor payable. kferret dismissed this as a self-serving line he expects Armor to invoke whenever convenient.

Finally, Armor argued that since no arCore Protect users or arNFT holders suffered material losses from the Yearn hack, it was best placed to decide how the claim should be used — opting to direct it toward shoring up the arNXM yield vault rather than paying kferret — while maintaining that it wanted an amicable outcome for all sides, including him. kferret called this dressing up a decision made entirely on Armor's terms as if it were some kind of mutual agreement.

The aftermath

Azeem and Armor subsequently published a tweetstorm reiterating the protocol's right to retain staked arNFTs, while offering kferret 500,000 ARMOR tokens as a gesture toward what they called a misunderstanding.

rekt can confirm that offer has not been accepted. kferret told us he has had no direct contact with the team since the dispute escalated and Armor sent the letter asserting it had final say over the matter. He said he stopped engaging once the team began using legal language, choosing instead to route further contact through his attorney, and hasn't reviewed anything sent to him since. He also believes he may have been banned from Armor's Discord as a result. Uncertain whether Umadbruhh has any legal training, he said he felt it was simply better to let lawyers deal with lawyers.

Where this leaves things

A token offer worth roughly a third of the disputed $1.6 million, extended only after the recipient was frozen out of the community, is not a gesture of goodwill by any reasonable standard. Insurance claims should not turn on an insurer's personal discretion, and this case shows a centralized team misrepresenting the status of a user's funds while unilaterally deciding to keep them. On the evidence here, neither Azeem nor Armor have earned continued trust — a CEO's assurances proved worthless the moment a claim became inconvenient, and the episode is a reminder that even in DeFi, an insurer's fine print still matters.

ArmorAzeem
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.