Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
WazirX security breach: How did hackers steal $230 million in crypto?
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Explainers
  • WazirX security breach: How did hackers steal $230 million in crypto?

WazirX security breach: How did hackers steal $230 million in crypto?

FP Explainers • July 22, 2024, 14:29:48 IST
Whatsapp Facebook Twitter

Indian crypto exchange WazirX has temporarily paused all trading after hackers stole $230 million in funds on Thursday. The company said the crypto was stolen from one of its multisig wallets, which need two or more private keys to validate and authorise transactions. Experts say the cybercriminal group Lazarus – which is affiliated with North Korea – could be behind the attack

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
WazirX security breach: How did hackers steal $230 million in crypto?
With 16 million customers, WazirX is one of India's most prominent crypto exchanges.

Indian crypto exchange WazirX has suffered a major hack, according to several media reports.

The exchange halted withdrawals on Thursday after $230 million in funds – nearly half its reserves – were stolen.

It called the incident a “force majeure” event that was “beyond its control.”

“We have already blocked a few deposits and reached out to concerned wallets for recovery. We are in touch with the best resources to help us in this endeavour,” the company said in a statement.

STORY CONTINUES BELOW THIS AD

But what happened? What do we know about the breach?

Let’s take a closer look:

What is Wazir X?

First, let’s take a brief look at WazirX.

WazirX is one of India’s biggest crypto exchanges.

More from Explainers
How ChatGPT is becoming everyone’s BFF and why that’s dangerous How ChatGPT is becoming everyone’s BFF and why that’s dangerous This Week in Explainers: How recovering from Gen-Z protests is a Himalayan task for Nepal This Week in Explainers: How recovering from Gen-Z protests is a Himalayan task for Nepal

It has over 16 million users.

Users on WazirX can buy and sell crypto such as Bitcoin, Ethereum, and Ripple among many others.

The company released a new interface earlier in July.

How did the hackers do it?

On 18 July, a hack saw $230 million stolen from WazirX’s multisig wallets.

Impact Shorts

More Shorts
Ghaziabad woman dead, pilgrims attacked in bus… How Nepal’s Gen-Z protests turned into a living hell for Indian tourists

Ghaziabad woman dead, pilgrims attacked in bus… How Nepal’s Gen-Z protests turned into a living hell for Indian tourists

Were bodyguards involved in Charlie Kirk’s shooting? The many conspiracies surrounding the killing

Were bodyguards involved in Charlie Kirk’s shooting? The many conspiracies surrounding the killing

“We’re aware that one of our multisig wallets has experienced a security breach. Our team is actively investigating the incident. To ensure the safety of your assets, INR and crypto withdrawals will be temporarily paused,” WazirX wrote on social media.

As per Economic Times, multisig wallets are a form of crypto wallet.

STORY CONTINUES BELOW THIS AD

These need two or more private keys to validate and authorise transactions.

As per The Hindu, the multisig wallet was being operated by six signatories – five from WazirX and one from digital asset service Liminal.

WazirX in a statement that the hacker perhaps used a difference between the data shown on Liminal’s interface and the transaction’s contents to steal the funds.

“The cyberattack stemmed from a discrepancy between the data displayed on Liminal’s interface and the transaction’s actual contents. During the cyberattack, there was a mismatch between the information displayed on Liminal’s interface and what was actually signed. We suspect the payload was replaced to transfer wallet control to an attacker,” it said.

“Despite us taking all necessary steps to protect the customer assets, the cyber attackers appear to have possibly breached such security features, and the theft occurred,” WazirX said.

Economic Times quoted Liminal as saying, “Our preliminary investigations show that one of the self-custody multisig smart contract wallets created outside of the Liminal ecosystem has been compromised.”

STORY CONTINUES BELOW THIS AD

“We can confirm that Liminal’s platform is not breached and Liminal’s infrastructure, wallets and assets continue to remain safe.”

Mint quoted data from blockchain analytics firm Lookonchain as showing that over $100 million worth of Shiba Inu (SHIB) tokens were stolen.

Bitcoin's total purse rockets up to $1 trillion as investors, ‘crypto-bros’ hype up resurgence
Data from blockchain analytics firm Lookonchain showed that over $100 million worth of Shiba Inu (SHIB) tokens were stolen. Ethereum tokens worth $52 million, Matic tokens worth $11 million, and Pepe tokens worth $6 million, were also hacked. Another $135 million in Tether and $3.5 million in Gala tokens were also stolen.

Ethereum tokens worth $52 million, Matic tokens worth $11 million, and Pepe tokens worth $6 million, were also hacked.

Another $135 million in Tether and $3.5 million in Gala were also stolen, as per Hindustan Times.

The Times of India quoted Cyvers, a Web3 security firm as saying that “multiple suspicious transactions” were detected regarding WazirX’s multisig wallet.

Cyvers said $230 million worth of crypto was moved to a new address.

STORY CONTINUES BELOW THIS AD

It said Tornado Cash – a fully decentralised protocol for private transactions on Ethereum – was used.

“The suspicious address has already swapped $PEPE (Pepe), $GALA (Gala), and $USDT (Tether) to $ETH (Ether) and continues to swap other digital assets,” Cyvers wrote_._

Hindustan Times quoted transactional data as showing that the thief was selling the stolen cryptos on the Uniswap on-chain exchange.

TechCrunch quoted risk-management platform Elliptic as saying that the hackers were ‘affiliated’ with North Korea.

Economic Times cited experts as saying that the cybercriminal group Lazarus could be behind this attack.

This group has previously executed some of the biggest crypto hacks in the world.

Victims have not got their funds back because the group did not negotiate.

Aditya Singh, a crypto watcher and influencer, told Economic Times, “If that’s true, the bad news is they do not cooperate, will never be held legally accountable, and are efficient with laundering,” he told ET.

“The freeze on 50% of WazirX’s assets is a pretty serious situation,” Singh added.

What is the company doing?

As per NDTV, the company has announced reward of $23 million for anyone who helps retrieve the stolen funds.

STORY CONTINUES BELOW THIS AD

WazirX has asked white hat hackers, blockchain forensics experts, and cybersecurity professionals to join the recovery efforts.

“This could potentially amount to $23 million, making it one of the largest bounties ever offered in the crypto industry,” the exchange said in a statement, as per NDTV.

“Our foremost goal is to recover the stolen funds. This bounty programme is designed to tap into the expertise of the community to achieve this critical objective,” WazirX founder Nischal Shetty said.

The company has also temporarily paused trading.

WazirX posted on social media: “The cyber attack theft has impacted our ability to maintain 1:1 collaterals with assets, and we’ve temporarily paused trading. We’re conducting thorough forensic data examination and security audit procedures and working to enable withdrawals soon. User safety remains our top priority. Thank you for your patience and support during this challenging time. We will continue to provide regular updates.”

The leaders of other crypto exchanges sought to reassure customers.

CoinSwitch co-founder Ashish Singhal wrote on social media, “We are aware of the recent security breach on the WazirX platform. We want to assure our users that their funds on CoinSwitch are secure and unaffected by this incident. We advise all our crypto investors to be mindful of potential market volatility during this time and exercise caution in their trading and investment activities.”

STORY CONTINUES BELOW THIS AD

Sumit Gupta, co-founder of CoinDCX said, “In light of the recent #WazirX breach, we want to reassure all CoinDCX users that your assets are safe and not impacted in any manner. Our wallet security remains robust."

Mudrex CEO Edul Patel, “We conduct regular audits to ensure a 1:1 ratio of funds. Additionally, our codebase goes through extensive scrutiny and review at many layers to ensure our tech infrastructure is immune to such exploits.”

But others are not so sanguine.

Mudit Gupta, a blockchain security researcher and chief information security officer at OxPolygon Labs, wrote on X, “RIP WazirX. Brace for another ‘crypto ban’ in India. Centralised exchanges are literally the opposite of decentralised finance and cryptocurrencies, but the politicians will use this hack to throw dirt at crypto. If you don’t understand it, ban it.”

With inputs from agencies

Tags
cryptocurrency
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

Ghaziabad woman dead, pilgrims attacked in bus… How Nepal’s Gen-Z protests turned into a living hell for Indian tourists

Ghaziabad woman dead, pilgrims attacked in bus… How Nepal’s Gen-Z protests turned into a living hell for Indian tourists

Prime Minister KP Sharma Oli resigned following violent protests in Nepal. An Indian woman from Ghaziabad died trying to escape a hotel fire set by protesters. Indian tourists faced attacks and disruptions, with some stranded at the Nepal-China border during the unrest.

More Impact Shorts

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV