WazirX: India
- Technique
- Signer Phishing
- Classification
- Social Engineering
- Target type
- CEX
- Affected chains
- Ethereum
- Source
- No public source link
On July 18, 2024, Indian exchange WazirX disclosed a breach of one of its multisig wallets, with roughly $234.9 million in assets drained — about 45% of the exchange's disclosed on-chain reserves at the time, according to CoinDesk. The attack didn't target WazirX's own smart contracts but the transaction-signing process inside the custody arrangement it shared with third-party provider Liminal Custody. Blockchain analytics firm Elliptic attributed the attack to North Korea's Lazarus Group within days.
How the attack worked
The wallet was a Safe (formerly Gnosis Safe) multisig requiring 4-of-6 signatures — five held by WazirX, one by Liminal. Per a technical writeup by QuillAudits, the attackers deployed a malicious contract and rehearsed the exploit through a fake exchange account eight days before executing it.
The core of the exploit wasn't phishing in the classic sense of a fake link — it was manipulation of what signers actually saw. According to Rekt, the attackers likely compromised two of the four required private keys directly, while the remaining approvals came through Liminal's transaction-verification interface: the screen showed signers what looked like a routine USDT transfer, while the transaction actually being signed carried a delegatecall that repointed the multisig proxy's implementation to an attacker-controlled address. Once that implementation swap went through, no fresh quorum was needed for subsequent transfers — the contract simply executed the attacker's logic on any following call. WazirX and Liminal publicly disagreed on where the substitution occurred: Liminal said the compromised wallet was "created outside the Liminal ecosystem," while WazirX said it suspected the payload was swapped during verification inside Liminal's own system.
This is the same attack class later used against Bybit in February 2025 — not a break of multisig cryptography, but deception of the humans who sign for it (blind signing / signature phishing). The haul wasn't just ETH: a large share was ERC-20 tokens — roughly $100 million in SHIB, plus MATIC, PEPE and others — later dumped through Uniswap.
Aftermath
WazirX froze both INR and crypto withdrawals immediately. Stolen funds moved through DEX swaps and the Tornado Cash mixer; per CoinDesk, tracing and freezing efforts had "limited success" — nothing was clawed back from the attacker itself.
Instead, WazirX halted trading for close to sixteen months and pursued a court-supervised restructuring under Singapore law through its parent entity, Zettai Pte. Ltd. In August 2025, creditors voted 95.7% by number and 94.6% by value in favor of the scheme, which Singapore's High Court approved in October 2025. Users were issued "recovery tokens" — claims on future payouts the exchange plans to buy back gradually out of trading revenue, not a return of the stolen assets themselves. Trading resumed on October 24, 2025.
A separate dispute concerns who bears responsibility: Binance maintained it only provided technical services and did not operationally run the exchange, complicating the question of who should make users whole.
What this implies
- A multisig's weak point isn't necessarily its cryptography — it can be the interface signers rely on to see what they're approving. Any custody arrangement where a signature is issued "blind," based on a third party's display, inherits this risk.
- There was no advance warning sign visible to users: until the implementation swap went live, the pending transaction looked identical to a legitimate one, both to signers and to any on-chain observer. This was a procedural failure inside the exchange's custody workflow, not something a depositor could have spotted.
- The same playbook — compromising multisig signing through interface manipulation rather than stealing private keys outright — resurfaced roughly a year later in the ~$1.5 billion Bybit hack, pointing to a repeatable attack methodology against CEX custody infrastructure rather than a one-off.
- "Funds returned" after such incidents can mean a debt obligation to repay users out of future revenue, not recovery of the stolen assets — a materially different risk profile from an insurance fund or an actual on-chain clawback.
Sources
- WazirX Hacked for $230M, Largely in SHIB, as Elliptic Says North Korea Behind Attack — CoinDesk ↗
- WazirX Restructuring Cleared, Bringing Massive Relief for $230M Hack Victims — CoinDesk ↗
- WazirX Rekt — Rekt ↗
- Another Lazarus Group Attack? Decoding WazirX Multisig Wallet's $235M Exploit — QuillAudits ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.