The WazirX Hack: India's Largest Crypto Exchange Lost $235 Million and Users Waited Over a Year to Get Most of It Back
WazirX told users its multi-signature wallet, custodied through a third party, was secure. A state-linked hacking group drained it of roughly $235 million in a single attack, and it took a Singapore court-approved restructuring running into 2026 before users saw most of their money return -- in a new token, not cash.
The Promise
โUser funds held on WazirX, India's largest cryptocurrency exchange by trading volume, were secured through an institutional multi-signature wallet arrangement custodied by a third party (Liminal Custody), designed to prevent unauthorised withdrawal even in the event of a compromise of any single signatory.โ
โ WazirX (operated by Zanmai Labs / Zettai Pte Ltd), India's largest cryptocurrency exchange by trading volume at the time ยท 1 January 2023
WazirX used a multi-signature wallet custody arrangement with Liminal Custody, requiring multiple approvals to authorise transactions, intended to protect the exchange's pooled user funds from being drained even if individual credentials were compromised.
The Standard
User funds protected by a multi-signature custody arrangement that could not be drained through a single point of compromise, consistent with standard practice for securing pooled cryptocurrency exchange assets.
Industry-standard multi-signature wallet security practices for cryptocurrency exchanges
In force from 1 January 2023
The Reality
On 18 July 2024, WazirX disclosed a cyberattack in which roughly $234.9 million in digital assets was stolen from its multi-signature wallet. Investigators found the attackers had created a fake WazirX account, used it to drain the hot wallet, then, after gaining sufficient access, altered the multi-signature wallet's underlying smart contract logic itself so that a routine-looking transaction signed by WazirX's own signatories actually handed the attackers full control, allowing them to drain the cold wallet as well. The attack was formally attributed by multiple governments to North Korea's Lazarus Group. WazirX suspended withdrawals, and its Singapore-incorporated parent, Zettai Pte Ltd, filed for a debt moratorium in the Singapore High Court to pursue a court-supervised restructuring rather than an outright liquidation. After more than a year of legal proceedings, creditors approved a restructuring scheme, and WazirX resumed trading on 24 October 2025. Under the scheme, users recovered about 85% of their pre-hack balances, with the remaining roughly 15% converted into Recovery Tokens credited to users by January 2026; as of mid-2026, no buyback of those tokens had been publicly confirmed, and the stolen funds themselves were reported to remain unrecovered, with the Lazarus Group having laundered the proceeds.
As of 18 July 2026
The Gap
Bars share a single zero-based scale. No axis truncation is used to exaggerate or minimize the gap between the two figures.
Money
Figures are in US dollars as reported at the time of the hack (equivalent to roughly โน2,000 crore); cryptocurrency values fluctuate significantly, so dollar-value figures reported by different sources at different dates vary.
Timeline
- AnnouncementHack disclosed
WazirX discloses that roughly $234.9 million in assets was stolen from its custodied multi-signature wallet, attributed to North Korea's Lazarus Group.
- StatusWithdrawals suspended, recovery options weighed
WazirX suspends withdrawals and co-founder Nischal Shetty says all options, including restructuring, are being considered for fund recovery.
- StatusSingapore moratorium filing
Zettai Pte Ltd, WazirX's Singapore-based parent, files for a debt moratorium in the Singapore High Court to pursue a court-supervised restructuring.
- MilestoneWazirX resumes trading
WazirX officially restarts trading after 95.7% of creditors approve the restructuring scheme.
- StatusRecovery Tokens credited
Recovery Tokens covering the remaining roughly 15% of user balances not repaid in the initial restructuring are credited to all eligible users.
Legal Status
This was a criminal cyberattack attributed to a foreign state-linked hacking group (North Korea's Lazarus Group), not a case of alleged wrongdoing by WazirX's own management, though separate, unrelated Enforcement Directorate scrutiny of WazirX over money-laundering and foreign exchange law concerns predates this hack. No individual attacker has been arrested or prosecuted in India in connection with the theft itself, consistent with the practical difficulty of prosecuting state-linked cybercriminals operating from abroad.
Verdict
That $234.9 million was stolen through a sophisticated compromise of WazirX's multi-signature wallet is not disputed -- it was independently attributed to the Lazarus Group by multiple governments. The unresolved question is recovery: over a year after the theft, none of the stolen funds themselves have been recovered, and users were made most of the way whole only through a restructuring that relied on the exchange's own remaining assets and a newly created token rather than recovered stolen property.
The hack's scale, the Lazarus Group attribution, and the Singapore restructuring timeline are corroborated across multiple independent industry and news sources. Confidence is not higher only because the final, long-term value users will realise from the Recovery Tokens (dependent on an unconfirmed future buyback) remains unresolved as of the most recent reporting reviewed.
What remains incomplete
- No confirmation was found of any of the stolen $234.9 million being recovered from the attackers as of mid-2026.
- The eventual real-world value of the 'Recovery Tokens' issued to users, contingent on an unconfirmed buyback, remains unresolved.
- The unrelated, pre-existing Enforcement Directorate inquiry into WazirX over money-laundering and FEMA concerns is a separate matter from this hack and is not comprehensively covered in this entry.
Sources
Related investigations
The 2G Spectrum Allocation Case
The CAG put the loss from underpriced telecom licences at โน1.76 lakh crore, once the country's most-quoted corruption figure. A decade later, a special court acquitted every single person accused of the underlying crime.
The GainBitcoin Cryptocurrency Ponzi Scheme
GainBitcoin promised investors 10% monthly returns in Bitcoin for 18 months through founder Amit Bhardwaj's mining and MLM network. Police called it one of India's biggest crypto Ponzi schemes โ estimates of the total loss range from roughly Rs 2,000 crore to figures in the billions of dollars โ and arrests and asset seizures were still happening as recently as 2024-2025, years after Bhardwaj's 2018 arrest and his 2022 death.
The Antrix-Devas Deal Case
ISRO's commercial arm signed away scarce S-band spectrum to a little-known start-up, then annulled the deal on national-security grounds after a political storm โ triggering an international arbitration award of over $560 million against India. A decade later, Indian courts found the underlying deal itself was procured by fraud, wound up Devas, and set the arbitration award aside, even as foreign courts have moved to enforce it anyway.