WazirX said on July 18, 2024, that a cyberattack on one of its multi-signature wallets had resulted in the theft of digital assets valued at more than $230 million. The Indian cryptocurrency exchange suspended cryptocurrency and Indian-rupee withdrawals as it attempted to contain the incident and trace the transferred assets.

The disclosure mattered beyond the size of the unauthorized transfers. The affected wallet used a multi-party approval process and third-party wallet infrastructure—controls intended to prevent any single compromised credential from moving funds. Their apparent failure raised immediate questions about transaction verification, exchange custody and whether customer balances remained fully backed.

What WazirX established

WazirX identified the affected Ethereum address as 0x27fD43BABfbe83a81d14665b1a6fB8030A60C9b4. Its preliminary report said the wallet had six signatories: five controlled by WazirX and one controlled by wallet-infrastructure provider Liminal. An ordinary transaction required signatures from three WazirX representatives using Ledger hardware wallets, followed by Liminal’s approval.

The exchange said destination-address whitelisting was also in place. Its preliminary explanation alleged a discrepancy between the transaction information shown through Liminal’s interface and the payload that was ultimately signed. WazirX suspected that the payload had been replaced in a way that transferred control of the wallet to the attacker.

Those statements described WazirX’s initial findings, not a completed independent forensic determination. Contemporaneous TechCrunch reporting documented both the withdrawal suspension and WazirX’s confirmation of the loss before the end of July 18. The reporting also recorded Liminal’s initial position that the compromised wallet had been created outside its ecosystem.

Measuring the scale

WazirX’s June 2024 proof-of-reserves release valued its holdings at 503.64 million USDT as of June 10, 2024, at 6:30 p.m. IST. Comparing the minimum disclosed theft of $230 million with that earlier figure produces approximately 45.7%, or about 46%.

That percentage is an indicative comparison, not a same-time balance-sheet calculation. The numerator was a preliminary dollar valuation from July 18, while the denominator measured company-reported holdings 38 days earlier. Token prices, deposits, withdrawals and wallet balances could all have changed between the two observations. The proof-of-reserves release also did not provide an independently audited, event-time reconciliation of every customer liability against every remaining asset.

The theft figure measured assets removed from the wallet at contemporaneous valuations. It did not establish each customer’s final loss, the amount ultimately recoverable, or a change in the value of the broader cryptocurrency market. No sufficiently controlled event window supports attributing a specific bitcoin, ether or market-wide price move to the breach.

Custody controls under scrutiny

Multi-signature arrangements distribute authorization, but their protection depends on what each signer can independently verify. If several signers approve misleading transaction data, the number of signatures alone does not prevent a malicious execution. WazirX’s preliminary account therefore pointed toward a failure involving the signing workflow rather than a simple theft of one private key.

Responsibility remained disputed. On July 29, Liminal said its platform, infrastructure and assets had remained secure and attributed the incident preliminarily to a customer-level compromise. That statement conflicted with WazirX’s emphasis on the interface and approval process. Neither account constituted a final public forensic finding, and the attack path was unresolved on July 18.

For customers, the immediate institutional consequence was simpler: displayed exchange balances could no longer be tested through withdrawal. Internal account records represented claims on WazirX, while the stolen tokens had moved on Ethereum. Without a contemporaneous asset-and-liability reconciliation, the size and distribution of the resulting customer shortfall remained uncertain.

Later clarification

In an affidavit dated August 27, 2024, WazirX operator Zettai’s director Nischal Shetty told the Singapore High Court that approximately $234 million had been taken at the time of the attack, close to half of the platform’s digital assets. The filing corroborated the incident’s scale and the July 18 withdrawal freeze, but it was not information available to customers when the breach was first disclosed.

Primary sourceWazirX — Preliminary Report: Cyber Attack on WazirX Multisig Wallet

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.