Home โบ Blockchain โบ WazirX Hack (2024)
๐ฎ๐ณ The WazirX Hack (2024)
Last verified: July 2026On 18 July 2024, India's largest cryptocurrency exchange lost $235 million to North Korean state-sponsored hackers โ despite genuinely robust security. Here's exactly what happened, why it worked, and what it took to make users whole again.
What happened
On 18 July 2024, WazirX โ India's largest domestic cryptocurrency exchange, with over 16 million registered users โ discovered that one of its main multi-signature wallets had been compromised. Attackers made off with approximately $234.9 million (around โน2,000 crore) in digital assets, spread across more than 190 different tokens, including roughly $96-102 million in Shiba Inu, $52.6 million in Ether, $11 million in Polygon (MATIC), and $7.6 million in Pepe. It represented nearly half of everything WazirX held at the time.
Why "robust" security still failed
This wasn't a case of an exchange cutting corners. WazirX's compromised wallet used a 4-of-6 multisignature setup โ five keys held by WazirX itself, and a sixth held by Liminal Custody, a third-party digital-asset custodian, with hardware-secured keys and an address-whitelisting system on top. On paper, this checked every box security experts recommend. The attackers didn't need to steal any of those keys directly. Instead, they deceived WazirX's own signers into approving what looked like a routine transaction, but was actually a malicious smart-contract upgrade to the wallet itself. Once that upgrade was approved by the required signatures, the attackers gained full control of the wallet โ no further keys needed, no further approvals required. The safeguard wasn't broken by force; it was walked through the front door because the door itself had been rebuilt without anyone noticing.
Who did it
Multiple independent security firms โ including Mandiant and Cyfirma โ linked the attack to the Lazarus Group, a hacking organisation widely assessed to operate on behalf of North Korea's intelligence services, historically responsible for some of the largest crypto heists on record (including the $530M Coincheck hack and numerous others). Investigators traced funds back to a wallet that had received seed funding from Tornado Cash โ a privacy tool often used to obscure the origin of illicit funds โ about eight days before the attack, suggesting real premeditation rather than an opportunistic strike.
The chaotic aftermath
WazirX immediately froze all withdrawals and reset user balances to their state just before the hack, reversing any trades made after the attack was discovered. The exchange then proposed spreading the losses proportionally across all users โ including those who held none of the stolen assets โ a plan that triggered significant user protest, since it meant everyone shared the pain regardless of what they'd actually been holding. One individual, arrested in connection with a "mule" account used to help facilitate the theft, was the only publicly reported arrest tied to the case.
The long road to recovery
What followed was over a year of restructuring. WazirX's Singapore-based parent entity pursued a formal restructuring process under Singapore law, and on 13 October 2025 โ more than 15 months after the hack โ the Singapore High Court sanctioned a creditor-approved recovery scheme, backed by roughly 96% of creditors. The plan returned approximately 85% of claim value to users and issued "Recovery Tokens" representing a claim on any future recovered funds. WazirX resumed trading operations on 24 October 2025.
What this actually teaches
The most important lesson isn't "avoid centralised exchanges" โ WazirX is a real, FIU-IND registered, legally compliant platform, and this could have happened to nearly any custodian trusting a multisig setup. The real lesson is sharper: a security system is only as strong as the process for verifying what you're actually signing, not just how many signatures it requires. This is also the single clearest real-world argument for self-custody for any amount you can't afford to lose entirely โ if you don't hold your own keys, your funds' safety ultimately depends on a company's internal processes working perfectly, every single time, against attackers actively trying to find the one moment they don't.
The India-specific angle
Because WazirX remained a going concern through restructuring rather than a total liquidation, the tax treatment of losses here is genuinely complicated โ partial recoveries, Recovery Tokens of uncertain value, and a multi-year timeline don't map cleanly onto standard capital-loss rules, and Indian crypto losses generally cannot be offset against other gains under current VDA tax law regardless. Anyone directly affected by this specific case should get professional tax advice rather than assume standard rules apply cleanly.