The WazirX wallet that lied to the people who signed it
India's biggest crypto exchange lost about $230 million in July 2024 when signers approved a transfer that did not match what their wallet showed. Researchers point to North Korea's Lazarus Group.
On July 18, 2024, WazirX — then India's largest cryptocurrency exchange — reported that roughly $230 million in digital assets had drained from one of its wallets. That was nearly half of the exchange's holdings, measured against an approximately $503 million proof-of-reserves report, per CloudSEK.
The wallet was a Safe multi-signature contract meant to make theft hard. Five keys were held by WazirX staff and one by the custody provider Liminal; moving funds required at least three WazirX signatures plus Liminal's, CloudSEK said. On paper, no single compromised person could drain it.
What was shown was not what was signed
WazirX traced the failure to "a mismatch between the information displayed on Liminal's interface and what was actually signed," the exchange said, as documented by CloudSEK. Signers believed they were approving a benign transaction; the payload they actually authorized handed control of the wallet to the attacker.
Once that malicious change went through, the intruder no longer needed WazirX's keys and emptied the wallet, according to the incident's Wikipedia record. Researchers attributed the operation to the Lazarus Group, citing tactical fingerprints and a KYC-verified Binance wallet tied to the attacker, per CloudSEK.
A long road back for users
Trading froze the same day. More than a year later, in October 2025, a Singapore court approved a restructuring that aimed to return roughly 85% of affected assets to users through a pro-rata scheme, and WazirX resumed operations with new custody arrangements, per its Wikipedia record.
Blind signing — approving a transaction you cannot fully read — is the thread running through this case. For anyone who signs on-chain:
- Verify the raw transaction on the signing device itself, not just the web interface that requests it.
- Treat a custody dashboard as untrusted display; the contract call is the truth, the UI is only a picture of it.
- Multisig protects against a stolen key, not against every signer being shown the same forged screen.
- Rehearse and hardware-verify large transfers; attackers studied WazirX's process for days before striking.
The comfort of a multisig is real but narrow. It stops one rogue key — not an adversary patient enough to deceive a quorum of honest signers at once.
— Sources: [CloudSEK](https://www.cloudsek.com/blog/wazirx-incident-explained) · [Wikipedia](https://en.wikipedia.org/wiki/2024_WazirX_hack)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING