T
iTokenly

WazirX hack — July 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$234,900,000Published estimates range $230,000,000 to $235,000,000Price at time of incident
MethodSocial engineeringSigners approved a malicious contract upgrade shown differently by the custody interface
ChainsEthereum
Attributed toNorth Korea (Lazarus Group)Suspected
OutcomeUnresolved

What happened

WazirX, then India's largest cryptocurrency exchange, lost about $234.9m on 18 July 2024 from a multisig wallet held under a custody arrangement with Liminal.

The wallet required three WazirX signatures plus one from Liminal. The attacker obtained approval for a malicious upgrade to the wallet's logic, after which the assets could be moved freely. Analysis points to a discrepancy between what the custody interface displayed and the transaction data actually being signed, meaning the signers approved something other than what they saw.

WazirX and Liminal have publicly disagreed about where responsibility lies, and no independent finding has settled the question. This entry records the mechanism as reported and does not assign fault between them.

Preparation began at least eight days earlier, with the operation funded through Tornado Cash on 10 July. The stolen assets included roughly $97m of SHIB and $53m of ETH. Several blockchain analysis firms have linked the attack to North Korea's Lazarus Group; that attribution has not been confirmed by any government, so it is recorded here as suspected.

Sources

  1. HalbornSecondary · retrieved 2026-08-01
  2. Crystal IntelligenceSecondary · retrieved 2026-08-01
  3. CPO MagazineSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "WazirX hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/wazirx
https://itokenly.com/hacks/wazirx

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.