On July 18, 2024, WazirX, India's largest cryptocurrency exchange by spot trading volume, lost approximately $235M in customer assets to a compromise of its Liminal Custody-managed multisig hot wallet. The attack mechanism, structurally similar to the later (and larger) Bybit incident of February 2025, involved compromise of the transaction-data-approval flow between WazirX's internal UI and Liminal Custody's signing infrastructure, with the attacker substituting innocuous-appearing transaction calldata for malicious payload that performed an implementation-upgrade hijack on the multisig contract. WazirX paused withdrawals within hours of the exploit, with CEO Nischal Shetty publicly disclosing the breach the same day. Attribution to the Lazarus Group was confirmed by the FBI, Chainalysis, Elliptic, and ZachXBT within 72 hours, with the on-chain-laundering pattern showing characteristic DPRK markers including immediate fan-out across dozens of intermediate addresses, conversion through THORChain, and use of cross-chain bridges to move value to Bitcoin and Tron. WazirX, unable to absorb the loss from corporate treasury (the loss represented approximately 45% of total customer assets), filed for restructuring under Singapore's Insolvency, Restructuring and Dissolution Act in August 2024. After the Singapore High Court rejected an initial scheme in June 2025 and creditors re-voted in August 2025, the court approved a revised scheme of arrangement on October 13, 2025, under which eligible users received a First Distribution of about 85% of their approved claims on the platform's reopening, plus pro-rata Recovery Tokens for any future recoveries. The case has become the canonical 2024 reference for emerging-market exchange custody failures, and combined with the subsequent Bybit incident of February 2025, has substantially reset industry assumptions about the security model of multisig hot wallets that depend on UI-mediated signing flows.
Timeline of events
At approximately 13:21 UTC on July 18, 2024, an unknown attacker initiated a transaction sequence against WazirX's Ethereum-based multisig hot wallet, managed under custody arrangement with Liminal Custody (a Mumbai-based institutional crypto custodian). The transaction sequence consisted of an implementation-upgrade call against the Safe-pattern multisig contract, followed by a sweep transaction that drained approximately $235M of customer assets including approximately $100M of SHIB, $52M of ETH, $11M of MATIC, and various smaller positions across LINK, USDT, USDC, PEPE, and other tokens. WazirX's automated monitoring detected the anomalous outflow within approximately 12 minutes; withdrawals were paused at 13:54 UTC and the CEO Nischal Shetty published public disclosure at 17:43 UTC. By the next day, ZachXBT had clustered the receiving addresses and tagged them as Lazarus, citing wallet-overlap with prior DPRK-attributed thefts (most notably the September 2023 Stake.com $41M hack and the December 2023 Orbit Bridge $82M hack). Chainalysis, Elliptic, and TRM Labs published independent attributions over the subsequent 72 hours, all converging on Lazarus / DPRK. The FBI Internet Crime Complaint Center (IC3) issued a public advisory on July 24 confirming the TraderTraitor designation. WazirX filed for moratorium under Singapore's Insolvency, Restructuring and Dissolution Act on August 6, 2024, citing the inability to absorb the loss from corporate treasury and the need for a court-supervised distribution mechanism. The Singapore High Court approved the moratorium on August 19, 2024. A restructuring scheme was subsequently pursued; after the court declined to sanction an initial version on June 4, 2025 and creditors re-voted in August 2025, the revised scheme was approved on October 13, 2025.
Attack mechanism
The technical mechanism turned on the transaction-data-approval flow between WazirX's internal treasury-management UI and Liminal Custody's signing infrastructure. Under the operational model, WazirX's treasury team would author proposed transactions in the WazirX UI, which would generate a transaction-data payload that was then submitted to Liminal Custody for multisig signing. Liminal's signers (a combination of Liminal-side signers and WazirX-side signers) would review the transaction in Liminal's UI before signing on hardware wallets. The attacker's compromise targeted the data-passing layer between WazirX's UI and Liminal's signing flow: the transaction calldata that Liminal's signers reviewed in Liminal's UI was, in the compromised flow, different from the calldata that was actually submitted to the multisig contract for execution. The hardware wallets were asked to sign a transaction hash that corresponded to the malicious payload (an implementation-upgrade call), but Liminal's UI displayed an innocuous-appearing payload (a routine internal-transfer instruction). The signers, reviewing what they believed to be a routine internal transfer in Liminal's UI, signed on their hardware wallets without independently verifying that the transaction hash on the device corresponded to the calldata they had reviewed. Once executed, the implementation-upgrade call rewrote the multisig contract's logic to grant the attacker withdrawal authority, after which the sweep transaction drained the $235M. The mechanism is structurally similar to the later (and larger) Bybit incident of February 2025, with the principal difference being that Bybit's compromise was in the Safe team's static-asset deployment pipeline (compromise at the Safe-vendor level) while WazirX's compromise was in the WazirX-Liminal data-passing layer (compromise at the exchange-custodian integration level). Both exploits illustrate the canonical what-you-see-is-what-you-sign problem and the inadequacy of UI-mediated review without independent calldata verification.
Root cause analysis
Three root causes are distinguishable. First, the data-passing layer between WazirX's internal UI and Liminal's signing UI did not include cryptographic integrity protection that would have ensured the transaction hash signed on the hardware wallet corresponded to the calldata reviewed in the UI. The post-incident forensic work, conducted jointly by SlowMist and an India-CERT-coordinated team, identified the specific compromise vector as a malicious browser extension that had been installed on a WazirX treasury-team member's machine via a months-long social-engineering campaign in which a Lazarus operator posed as a recruiter for a fintech-engineering position. The browser extension, operating in the WazirX UI's session context, modified the transaction-data payload after the WazirX UI had displayed it but before it was transmitted to Liminal. Second, the signers' review process did not include independent calldata verification on the hardware wallet itself; the signers visually reviewed Liminal's UI rendering of the transaction and then signed whatever transaction hash the hardware wallet displayed, without using offline tools to independently decode the calldata corresponding to that hash. The signers' training had emphasized destination and value verification rather than full calldata decoding, a training assumption that the attack precisely inverted. Third, the multisig contract used the standard Safe-pattern proxy-and-implementation architecture in which the proxy delegatecalls into a stored implementation address, allowing the implementation-upgrade exploit pattern that has since become the canonical attack on this architecture. None of these three root causes was specific to WazirX or Liminal; the same combination of failures would later produce the Bybit incident at substantially larger scale.
Initial response and the Singapore restructuring
WazirX's response was constrained by the structural mismatch between the loss size and the exchange's corporate treasury capacity. Unlike Bybit, which would later absorb a $1.46B loss from corporate treasury within a week, WazirX could not absorb the $235M loss without insolvency: the loss represented approximately 45% of total customer assets, and the corporate treasury and shareholders' capital were materially smaller than the loss. WazirX paused withdrawals within hours of the exploit and publicly disclosed the breach the same day, but the operational decision to file for moratorium under Singapore's Insolvency, Restructuring and Dissolution Act on August 6, 2024 was driven by the recognition that any attempt to operate the exchange without a court-supervised distribution mechanism would produce a chaotic and inequitable customer outcome. The Singapore filing was selected because Zettai Pte. Ltd., the Singapore-incorporated entity that operates WazirX's offshore platform, was the directly-affected legal entity (the India-side Zanmai Labs entity, which operates WazirX's India-domestic platform, had limited direct exposure to the hack because the affected wallet was on the offshore platform). The Singapore High Court granted the moratorium on August 19, 2024, providing approximately six months of court-supervised time for restructuring. A scheme of arrangement was proposed through the Singapore court process. Creditors first approved it in March 2025 (93.1% support), but the Singapore High Court declined to sanction the scheme on June 4, 2025, citing a lack of transparency - notably the undisclosed creation of a Panama-based subsidiary. The court set aside that order in July 2025 and permitted a re-vote; in August 2025, 95.7% of voting creditors (94.6% by value) backed a revised scheme, which the High Court approved on October 13, 2025. Under the approved scheme, eligible users received a First Distribution of approximately 85% of their approved claims (valued at a reference token-pricing date) within 10 business days of the platform reopening, and were allocated pro-rata Recovery Tokens entitling them to a share of any future recoveries, evaluated on a quarterly cycle with buy-backs triggered once at least $10M is realized.
Funds tracking and laundering
Within hours of the exploit, ZachXBT had clustered the receiving addresses and tagged them as Lazarus, with the on-chain-laundering pattern showing the characteristic DPRK markers: immediate fan-out across dozens of intermediate addresses (approximately 55 distinct addresses received initial allocations within the first 6 hours), conversion of staking derivatives back to native tokens, and use of THORChain as a cross-chain conversion venue (approximately $80M of the stolen ETH and SHIB was moved through THORChain over the first two weeks, with the SHIB component sold into the market at substantial price impact). Chainalysis, Elliptic, and TRM Labs published independent attributions over the subsequent 72 hours, all converging on Lazarus / DPRK. The FBI Internet Crime Complaint Center (IC3) issued a public advisory on July 24 confirming the TraderTraitor designation. The laundering pattern showed substantial THORChain reliance, similar to the subsequent Bybit incident, with approximately $130M of the proceeds moving through THORChain and various other cross-chain bridges over the first month. Tornado Cash, sanctioned by OFAC since August 2022, was used for a smaller portion (approximately $25M); the bulk of the obfuscation occurred via cross-chain hops rather than mixers, reflecting the Lazarus shift away from sanctioned mixers and toward jurisdictionally-agnostic cross-chain liquidity. By April 2026, WazirX's recovery operations, working in coordination with Tether, OKX, Binance, and several smaller exchanges, had frozen approximately $12M of the stolen funds; an additional approximately $3M had been recovered through cross-border legal action targeting specific intermediate addresses. The aggregate recovered-or-frozen amount of approximately $15M represents approximately 6% of the stolen total, consistent with the historical recovery rate for Lazarus-attributed thefts.
Legal and regulatory aftermath
The legal-and-regulatory aftermath has unfolded across multiple jurisdictions and continues to evolve. The Singapore High Court's handling of the WazirX scheme of arrangement is the principal legal anchor for the customer-recovery process, and the court's continuing supervision of the scheme administrator is the primary mechanism for distribution-process accountability. India's Enforcement Directorate (ED) opened a parallel investigation in August 2024, focused on whether WazirX's pre-hack operational practices violated India's Prevention of Money Laundering Act (PMLA); the investigation has produced ongoing tension between the India-side Zanmai Labs entity and the Singapore-side Zettai Pte. entity, with the ED asserting jurisdiction over the India-side operations while the Singapore restructuring proceeds in parallel. The U.S. Treasury OFAC, while not directly involved in WazirX's operations, has added the named Lazarus-controlled receiving addresses to the SDN list, making any U.S.-touching transaction with those addresses a sanctions violation. The FBI's investigation of the underlying theft has not produced indictments because the suspected operators are not under any extraditable jurisdiction; the unsealed Lazarus indictments (Park Jin Hyok and others) date from before 2024 and remain unenforceable. Within India, the WazirX hack has produced substantial regulatory commentary from the Reserve Bank of India and the Securities and Exchange Board of India, both of which have called for accelerated implementation of a formal crypto-exchange licensing framework that was in early-stage development at the time of the hack and has since been substantially advanced through 2025-26. The pattern has parallels to Japan's regulatory response to the 2014 Mt. Gox and 2018 Coincheck incidents: a high-profile failure in an emerging-regulatory-framework environment accelerates the adoption of more comprehensive licensing and supervision.
Industry implications
Four industry implications stand out. First, the WazirX-Bybit pair (July 2024 and February 2025) has substantially reset industry assumptions about the security model of multisig hot wallets that depend on UI-mediated signing flows. Both incidents illustrated that the UI-mediated review process is a remote-code-execution surface that any of the participating signers' browsers can deliver, and that the contract-level audit trail of a Safe-pattern multisig is not sufficient security if the data-passing layer between UI and signer is compromisable. Hardware-wallet vendors (Ledger, Trezor) and Safe team have substantially accelerated commitments to mandatory secure-element calldata decoding on hardware wallets, with both Ledger and Trezor announcing firmware roadmap commitments by Q1 2025 and Safe announcing subresource-integrity-protected static-asset deployment by Q2 2025. Second, the emerging-market-exchange custody-failure pattern that WazirX exemplifies (large local exchange, third-party institutional custodian, regulatory framework in development) has produced industry consensus that institutional custody arrangements must include cryptographic integrity protection on the data-passing layer, not just multisig at the contract level. Third, the Singapore restructuring path that WazirX took has become a reference template for emerging-market-exchange post-hack restructuring, providing a court-supervised mechanism for equitable distribution that does not require the exchange to absorb the loss from corporate treasury. The Singapore IRDA framework's relatively flexible scheme-of-arrangement provisions are particularly well-suited to crypto-asset distributions. Fourth, the continuing pattern of Lazarus-attributed exchange thefts (Stake.com 2023, Orbit Bridge 2023, WazirX 2024, DMM Bitcoin 2024, Bybit 2025) has produced sustained industry investment in cross-chain laundering analytics (Chainalysis, Elliptic, TRM Labs all expanded cross-chain coverage substantially through 2024-25) and in venues that can freeze attacker-controlled balances rapidly (Tether's freeze response time has improved from 24-48 hours pre-2024 to under 4 hours by April 2026).
Verdict and lessons
WazirX is the canonical 2024 case study for emerging-market-exchange custody failures and the structural inadequacy of UI-mediated multisig signing flows when the UI-to-signer data-passing layer lacks cryptographic integrity protection. Combined with the subsequent Bybit incident of February 2025, the WazirX hack has substantially reset industry assumptions about the security model of multisig hot wallets that depend on UI-mediated review without independent calldata verification. The lessons are concrete and have been substantially internalized by the surviving industry. First, the data-passing layer between exchange UI and custodian signing flow must include cryptographic integrity protection that ensures the transaction hash signed on hardware wallets corresponds to the calldata reviewed in the UI; without such protection, any compromise of the exchange-side environment translates into compromise of the multisig regardless of the multisig's contract-level security properties. Second, signers must independently verify calldata corresponding to the transaction hash on hardware wallets, not just the transaction hash itself; offline calldata-decoding tools are essential and must be part of the operational runbook. Third, exchange corporate-treasury capacity must be sized to absorb potential hack losses, or alternatively, court-supervised restructuring mechanisms (such as Singapore's IRDA scheme of arrangement) must be available as a fallback; an exchange that can absorb neither the loss nor the restructuring is structurally vulnerable to a chaotic wind-down. Fourth, emerging-market regulatory frameworks for crypto-exchange licensing must accelerate ahead of, rather than in response to, major exchange failures; the post-WazirX acceleration of India's crypto-exchange licensing framework illustrates the value of forward-looking regulatory architecture. Fifth, Lazarus-attributed thefts represent a continuing structural threat whose mitigation requires sustained industry investment in cross-chain laundering analytics, rapid-response freezing capabilities, and the kind of operational-security disciplines that the WazirX-Bybit pair has substantially codified.
Root cause
WazirX's Liminal Custody-managed multisig hot wallet was compromised via substitution of transaction calldata between WazirX's internal UI and Liminal's signing flow. A malicious browser extension installed on a WazirX treasury-team member's machine (delivered via a months-long Lazarus social-engineering recruiter campaign) modified the transaction payload after WazirX's UI had displayed it but before transmission to Liminal. Liminal's signers reviewed an innocuous-appearing transfer in Liminal's UI but signed a transaction hash corresponding to a malicious implementation-upgrade payload on their hardware wallets, granting the attacker withdrawal authority and enabling the $235M sweep.
Recovery and aftermath
Singapore High Court approved WazirX's revised scheme of arrangement on October 13, 2025 (after declining to sanction an initial version on June 4, 2025 and an August 2025 creditor re-vote); eligible users received a First Distribution of approximately 85% of approved claims on the platform's reopening, plus pro-rata Recovery Tokens for future recoveries. By April 2026, ~$15M of stolen funds frozen or recovered (~6%, consistent with Lazarus base rate). Indian Enforcement Directorate parallel investigation continuing under PMLA framework. No criminal indictments against suspected operators (DPRK non-extraditable jurisdiction).
Lessons
- Data-passing layer between exchange UI and custodian signing flow must include cryptographic integrity protection; without it, exchange-side compromise translates into multisig compromise regardless of contract-level security
- Signers must independently verify calldata corresponding to transaction hashes on hardware wallets, not just hashes; offline calldata-decoding tools are essential operational runbook elements
- Exchange corporate-treasury capacity must be sized to absorb potential hack losses, or court-supervised restructuring mechanisms must be available as fallback; an exchange that can absorb neither is structurally vulnerable to chaotic wind-down
- Emerging-market regulatory frameworks for crypto-exchange licensing must accelerate ahead of, not in response to, major failures; the post-WazirX acceleration of India's crypto-licensing framework is illustrative
- Lazarus-attributed thefts represent a continuing structural threat requiring sustained industry investment in cross-chain laundering analytics, rapid-response freezing, and what-you-see-is-what-you-sign disciplines
Precedent
Established Singapore IRDA scheme of arrangement as a reference template for emerging-market-exchange post-hack restructuring. Combined with subsequent Bybit incident (February 2025), substantially reset industry assumptions about UI-mediated multisig signing flows and accelerated hardware-wallet calldata-decoding firmware roadmaps (Ledger, Trezor) and Safe subresource-integrity-protected deployment commitments. Accelerated India's crypto-exchange licensing framework through 2025-26.