WazirX

#WazirX • 2024-07

🇮🇳 India

WazirX recently experienced a cyber attack on one of its multisig wallets, leading to a loss of over $230 million. This wallet, managed using Liminal’s digital asset custody services since February 2023, had six signatories: five from WazirX and one from Liminal. Transactions required approvals from three WazirX signatories and one from Liminal, with a policy to whitelist destination addresses to enhance security.

The attack exploited a discrepancy between the data shown on Liminal’s interface and the actual transaction contents. The attackers likely replaced the transaction payload, enabling them to gain control of the wallet.

Despite robust security measures, including the Gnosis Safe multisig platform and Liminal’s whitelisting policy, the attackers breached these defenses. WazirX is actively working to recover the stolen funds, having already blocked some deposits and reached out to relevant wallets.

WazirX emphasizes their commitment to transparency and is continually investigating the incident, seeking to recover the funds and strengthen their security to prevent future attacks.

Affected Wallet Address: 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4

Related Actors

Lazarus

Novetta

Novetta coined the name "Lazarus Group" as part of Operation Blockbuster, an industry coalition it led with partners including Kaspersky Lab and Cisco Talos that publicly disclosed its findings on 24 February 2016. Kaspersky's contribution to that release traced the actor's activity back to 2009, noted a spike from 2011 and steady growth from 2013, and folded malware and campaigns previously tracked separately, including Operation Troy, DarkSeoul, Hangman (2014-2015) and Wild Positron/Duuzer (2015), into a single cluster alongside the malware publicly attributed to the Sony Pictures Entertainment (SPE) breach. Novetta's own reverse engineering identified a spreader built specifically with SPE network and account details to deliver a destructive wiper. Across the analyzed malware set the group fielded a large toolkit of remote-administration trojans built on a shared code base, worm-style network spreaders, peer-to-peer staging tools, and web-server backdoors, alongside spearphishing that included a Hangul Word Processor zero-day, password-protected ZIP droppers, self-deleting batch scripts, and sandbox-evasion checks. Targets spanned financial, media and manufacturing organizations with a recurring focus on South Korea, and operations blended cyberespionage with destructive, data-wiping attacks.

Operation Blockbuster
First seen: 2016-02 • Last seen: 2026-08

Related Reports

« Back