[ newsletter ]
Stay ahead of Web3 threats—subscribe to our newsletter for the latest in blockchain security insights and updates.
Thank you! Your submission has been received!
Oops! Something went wrong. Please try again.
WazirX reveals initial findings following a cyber attack that resulted in a loss of over $230 million. The company outlines the breach mechanics and its recovery efforts.
Hours after the prominent Indian cryptocurrency exchange WazirX suffered a significant cyber attack resulting in a loss exceeding $230 million, the company has disclosed its preliminary findings regarding the incident. The attack targeted one of its multisig wallets, which was managed using Liminal’s digital asset custody and wallet infrastructure since February 2023.
The cyber attack on WazirX was executed through a multisig wallet that required multiple approvals for transactions. The wallet had six signatories: five from WazirX and one from Liminal. Typically, a transaction needed the approval of three WazirX signatories, all of whom utilized Ledger Hardware Wallets for enhanced security, followed by the final approval from Liminal’s representative.
However, the attackers managed to exploit a flaw in the system. They swapped various assets, including Tether, Pepe, and Gala, for Ether before the breach was publicly acknowledged.
WazirX provided insights into the wallet's configuration and the mechanics of the breach:
The company suspects that the attack stemmed from a mismatch between the data displayed on Liminal’s interface and the actual transaction contents. This discrepancy may have allowed the attackers to replace the payload, effectively transferring control of the wallet to them.
In light of the attack, WazirX has categorized the incident as a “force majeure,” indicating that it was beyond their control. The company is taking several steps to mitigate the damage and recover the lost funds:
Despite implementing robust security measures, the company acknowledged that the attackers managed to breach these defenses, leading to the theft. WazirX remains committed to protecting customer assets and is actively pursuing all avenues to recover the lost funds.
The WazirX cyber attack serves as a stark reminder of the vulnerabilities present in the cryptocurrency space. As the company works diligently to recover from this incident, it highlights the importance of continuous security enhancements and vigilance in safeguarding digital assets.