WazirX Hack Aftermath: North Korean Hackers Suspected of Stealing Funds From Indian Crypto Exchange

WazirX has confirmed that it lost funds exceeding $230 million (roughly Rs. 1,924 crore) after being hacked.

Advertisement
Written by Radhika Parashar, Edited by David Delima | Updated: 19 July 2024 16:16 IST
Highlights
  • One of WazirX’s wallet was hacked on July 18
  • The affected wallet was under the oversight of Liminal Custody
  • More information on attackers remains awaited

WazirX was founded in 2018 and is headquartered in Mumbai, India

Photo Credit: Unsplash/ Towfiqu Barbhuriya

WazirX was impacted in a data breach on Thursday, as the company lost funds worth $230 million (roughly Rs. 1,924 crore) to hackers. Over the past 24 hours, analysts and crypto industry executives have identified reasons to believe that this sophisticated breach could have been initiated by North Korean hackers, possibly linked to the infamous Lazarus Group. In a conversation with Gadgets360, Polygon's chief information security officer, Mudit Gupta, said that there was "80 percent" certainty of the involvement of North Korean hackers in the WazirX data breach.

Crypto Industry Offers Advice as WazirX Confirms Stolen Funds

WazirX has confirmed that the hack led to the loss of funds exceeding $230 million (roughly Rs. 1,924 crore). The exchange partnered with Liminal Custody Solutions in February 2023 for assistance in secure crypto storage. In this hack, the hackers managed to get access to two signatures from WazirX and one from Liminal to hack this multi-signature wallet where the stolen funds were being held.

Meanwhile, executives from the crypto industry have offered insights into the WazirX incident, even commenting on the security of the crypto exchange.

Advertisement

Arjun Vijay, the co-founder and COO of Giottus crypto exchange, first said that no exchange should concentrate such a significantly large part of their total value held – in one hot wallet that is always at risk of being violated by malicious actors. His views were echoed by Gaurav Arora, Founder of Spenny, an investment platform.

Advertisement

“If they had capped each wallet at $25 million or even $50 million, we wouldn't be facing this disaster. This is sheer laziness on WazirX's part. On Liminal's part, they should have implemented a security mechanism to block suspicious transactions. Since Liminal is not a dApp, they can have a manual intervention to confirm such big transactions, perhaps via a call or another secure method,” Arora said.

Polygon's Gupta alleged that WazirX has 'no security personnel'. “For comparison, Coinbase has over 200 people doing security and compliance,” he told Gadgets360, noting that an in-house security expert can set up procedures and ensure that the best practices are being followed when signing transactions as well as while also verifying everything being signed.

Advertisement

We've reached out to WazirX for details about its in-house security arrangements and are awaiting a response from the crypto exchange.

WazirX Hack: How Hackers Stole Funds From the Crypto Firm

In a statement shared with Gadgets360, WazirX detailed how the incident unfolded on Thursday. “A cyber attack occurred in one of our multisig wallets, which was operated utilising Liminal's digital asset custody and wallet infrastructure. The wallet had six signatories—five from our WazirX team and one from Liminal. During the cyber attack, there was a mismatch between the information displayed on Liminal's interface and what was actually signed. We suspect the payload was replaced to transfer wallet control to an attacker,” the WazirX team said.

Advertisement

The Mumbai-based exchange said this incident happened despite it having deployed security features including the Gnosis Safe multisig smart contract platform and Liminal's whitelisting policy. The withdrawal and deposit services on the platform remain halted on WazirX after the exchange paused them on Thursday.

“This is a force majeure event beyond our control, but we are leaving no stone unturned to locate and recover the funds. We have already blocked a few deposits and reached out to concerned wallets for recovery,” the exchange said on Friday in a post on X (formerly Twitter).

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  2. Vivo X300 Series Price, Key Features Leaked Ahead of Global Launch
  3. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  4. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  5. Idli Kadai Starring Dhanush Now Streaming on Netflix: What You Need to Know
  6. Nothing Phone 3a Lite First Impressions
  7. Oppo Enco X3s Launched With 55dB ANC, Up to 45 Hours Total Battery Life
  8. Moto G67 Power 5G India Launch Date, Key Features Announced
  1. NASA’s X-59 Supersonic Jet Takes Historic First Flight, Paving Way for Quiet Supersonic Travel
  2. ASIC Clarifies Crypto Rules; Stablecoins, Tokenised Assets Flagged as Financial Products
  3. SpaceX Launches 28 Starlink Satellites, Lands Falcon 9 Booster in Pacific
  4. Idli Kadai, Starring Dhanush, Now Streaming on Netflix: What You Need to Know
  5. Ideabaaz Now Streaming on ZEE5: Everything You Need to Know
  6. Grey’s Anatomy Season 22 OTT Release: Know Where to Watch it Online?
  7. Bad Girl OTT Release Date: When and Where to Watch Tamil Drama Online?
  8. Adobe Partners With Google Cloud to Integrate Frontier AI Models Across Its Platforms
  9. Vivo X300, Vivo X300 Pro Price and Key Specifications Leaked Ahead of Global Launch
  10. OnePlus 15 India Launch Date Announced; to Debut as First Snapdragon 8 Elite Gen 5 Phone in India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.