WazirX advised customers on July 20, 2024, to refrain from trading on its cryptocurrency exchange while it investigated the theft of digital assets valued by the company at more than $230 million.
The warning represented an unusual intermediate state for a centralized exchange: customers could still see and trade account balances, but deposits and withdrawals had already been suspended following the July 18 attack. WazirX’s surviving day-by-day incident record says the exchange continued coordinating with other trading venues and law-enforcement agencies on July 20, while specifically warning users not to trade during what it called a critical period.
That development mattered because trading inside a closed exchange does not itself move assets onto a public blockchain or prove that the venue possesses every token represented in customer accounts. With withdrawals unavailable, customers could not independently test whether displayed balances remained redeemable. The July 20 warning therefore shifted the immediate concern from containment of one compromised wallet to the reliability and settlement of the exchange’s wider internal market.
What was established by July 20
WazirX had confirmed on July 18 that one multi-signature wallet was compromised. Its preliminary account valued the resulting loss above $230 million and said the wallet had used infrastructure supplied by digital-asset custody technology provider Liminal.
The exchange described a six-signatory configuration: five signatories managed by WazirX and one by Liminal. Its stated transaction process ordinarily required approval from three WazirX signatories using Ledger hardware wallets, followed by approval from Liminal. That description was WazirX’s preliminary account, not an independently completed forensic finding.
CoinDesk reported on July 18 that the compromised assets included a large concentration of SHIB and that blockchain analytics company Elliptic suspected a North Korea-linked attacker. Attribution remained an external analytical assessment on July 20; neither WazirX nor an identified government agency had published a conclusive finding.
By July 19, WazirX said it had begun contacting more than 500 exchanges to seek the blocking of identified addresses, engaged law-enforcement agencies and forensic specialists, and suspended both cryptocurrency and Indian-rupee deposits and withdrawals. The number of exchanges was a company-reported outreach count. It did not establish that 500 venues had responded, frozen assets or recovered funds.
A market without external settlement
The July 20 trading warning exposed the difference between an exchange’s internal ledger and on-chain custody. A customer trade could alter the account balances recorded by WazirX without moving the corresponding assets from one blockchain address to another. That structure is normal for centralized exchanges, but it becomes consequential when a large reserve wallet has been emptied and redemptions are disabled.
No public, independently audited reconciliation available on July 20 established the exchange’s remaining assets, total customer liabilities or the shortfall attributable to each token. The figure above $230 million measured WazirX’s estimate of assets taken from the wallet, not customer losses finally adjudicated, recovered assets, or a movement in the broader cryptocurrency market.
The parties also disputed responsibility. WazirX’s preliminary explanation focused on a mismatch between what its signers believed they were approving and what was executed on-chain. Liminal said its platform, wallets and assets had not been breached. Those were competing contemporaneous claims, and the public record on July 20 did not resolve the intrusion method.
Later clarification
On July 21, WazirX formally suspended trading and said the theft had impaired its ability to maintain one-to-one asset collateralization. It also announced a recovery bounty. Those actions clarify why the July 20 warning was significant, but they had not yet occurred when customers were first advised to stop trading. Root cause, attribution, recoveries and customers’ ultimate legal treatment remained unresolved at the end of July 20.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

