WazirX: India Hack

REPORTED LOSS $235M
Critical Safe Multisig wallet Phishing Exploit ethereum

What happened

On July 18, 2024, WazirX suffered a theft of more than $230 million in digital assets from a multisignature wallet using Liminal's wallet infrastructure. The companies disputed how the wallet was compromised. WazirX suspended deposits, withdrawals and trading in response.

Technical Root Cause

WazirX's preliminary report described a mismatch between the displayed transaction and signed payload. Liminal denied a breach of its infrastructure and described the affected wallet as a customer self-custody wallet. The reviewed reports do not establish a mutually agreed initial compromise or prove how the attacker obtained control.

Case & protocol details

Classification Infrastructure / CeFi / Social Engineering
Protocol Type Exploit/Access control
Official Website wazirx.com/signup
Protocol Twitter/X @WazirXIndia

How it happened

  1. According to WazirX, the wallet normally required approval from three WazirX signatories followed by Liminal's signatory.
  2. WazirX reported that the transaction data displayed to its signers differed from what they signed, and suspected that a substituted payload transferred wallet control to the attacker.
  3. Assets worth more than $230 million were stolen from the affected wallet.
  4. WazirX suspended deposits, withdrawals and trading while investigating and pursuing the stolen funds.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.