The WazirX hack was a $234.9 million (roughly Rs1,960 crore) theft from WazirX’s Ethereum multisig wallet on 18 July 2024. Attackers manipulated the signing interface to hijack wallet ownership. Withdrawals were suspended immediately and remain partially restricted as of mid-2026, with affected users receiving recovery tokens rather than a direct refund.
Key Takeaways
- Hackers stole roughly $234.9 million from WazirX’s Safe multisig wallet on 18 July 2024, according to on-chain data cited by blockchain security firm Elliptic.
- The attack exploited a mismatch between what WazirX’s signers saw in their Liminal custody interface and what was actually being signed on-chain.
- WazirX suspended withdrawals immediately and has not fully restored them as of mid-2026.
- A restructuring proposal filed in Singapore courts offers affected users recovery tokens redeemable over time, not an immediate full refund.
- The WRX burn event is part of the broader plan to stabilise the ecosystem, though its direct benefit to hack victims remains limited.
How the WazirX Hack Happened
The Multisig Wallet Setup
WazirX used a multi-signature wallet managed jointly with custody provider Liminal. A multisig setup requires multiple private-key holders to approve any transaction before funds move. The WazirX hack exposed a dangerous gap between the user interface and the actual blockchain transaction. You can read more about how multisig setups work and where they can fail in our multi-sig wallets explained guide.
The Attack in Detail
Attackers manipulated the transaction payload so that WazirX’s authorised signers approved what looked like a routine operation in the Liminal dashboard, but the underlying smart-contract call was swapping wallet ownership to the attacker’s address. The attacker then upgraded the Safe wallet’s implementation contract immediately after gaining control, making the theft irreversible within minutes.
Blockchain forensics firm Elliptic identified on-chain transaction patterns consistent with North Korea-linked group Lazarus Group as the likely attacker, a finding echoed by independent researchers. Roughly 200+ tokens were drained, including large positions in SHIB, ETH, MATIC, and PEPE. The stolen funds were quickly routed through Tornado Cash and other mixing protocols to obscure the trail. This kind of attack sits at the intersection of social engineering and smart-contract exploitation, which is why standard password security alone does not protect against it. Our crypto wallet security guide covers the broader threat landscape in detail.
WazirX vs. Liminal: Who Is Responsible?
Both WazirX and Liminal publicly blamed each other in the days after the breach. WazirX claimed Liminal’s infrastructure was compromised; Liminal maintained its systems were intact and the breach originated on WazirX’s side. As of mid-2026, no Indian court has issued a final ruling on liability, and litigation is ongoing.
WazirX Hack Recovery and Restructuring Timeline
Immediate Response (July 2024)
WazirX halted all INR and crypto withdrawals on 18 July 2024, hours after the WazirX hack was detected. The exchange filed a police complaint and notified the Financial Intelligence Unit (FIU-IND). It also reached out to 500+ exchanges globally to blacklist the stolen wallet addresses.
Socialised Loss Model (August 2024)
Unable to cover the full shortfall, WazirX announced a socialised loss model. Under this approach, all users, not just those whose tokens were directly stolen, would bear a proportional share of the loss. According to WazirX’s official August 2024 announcement, users could access only about 55% of their holdings in liquid assets; the remaining 45% was locked in USDT-equivalent tokens representing the stolen portion. This drew significant backlash from the Indian crypto community.
Singapore Moratorium (September 2024)
WazirX’s parent entity Zettai Pte Ltd filed for a moratorium in Singapore’s High Court in September 2024 to get legal breathing room from creditors. The Singapore court granted an interim moratorium, pausing legal claims against the company while a restructuring plan was worked out.
Restructuring Proposal (Early 2025)
WazirX announced a formal restructuring proposal in early 2025. The plan involved issuing recovery tokens to affected users, representing their claim on future recovered or generated funds. These tokens would be redeemable over a multi-year period as the exchange rebuilt revenue and potentially recovered stolen assets. The proposal required creditor approval under Singapore’s insolvency framework.
WRX Burn Event
As part of efforts to stabilise the WRX token economy, WazirX announced a WRX burn event, reducing the circulating supply of its native token. Token burns can create deflationary pressure on price, but they do not directly compensate hack victims. The burn was positioned as an ecosystem health measure rather than a direct recovery mechanism for those affected by the WazirX hack.
Status as of Mid-2026
Withdrawals remain partially restricted for affected users as of July 2026. Some users with unaffected balances have reportedly been able to access funds through a phased withdrawal process, but those holding the locked recovery tokens are still waiting. The restructuring vote outcome and timeline for recovery token redemption are the two most critical pending milestones.
| Date | Event | Status |
|---|---|---|
| 18 July 2024 | WazirX hack occurs; $234.9M drained from multisig wallet (source: Elliptic) | Confirmed |
| July 2024 | Withdrawals suspended; FIU-IND notified; 500+ exchanges contacted to blacklist addresses | Confirmed |
| August 2024 | Socialised loss model announced; users access 55% of holdings in liquid assets (source: WazirX official announcement) | Confirmed |
| September 2024 | Singapore moratorium filed by Zettai Pte Ltd and interim moratorium granted | Confirmed |
| Early 2025 | Formal restructuring proposal with recovery tokens submitted for creditor approval | Proposed |
| 2025-2026 | WRX burn event announced to reduce circulating supply | Announced |
| Mid-2026 | Partial withdrawals ongoing; recovery token redemption timeline unconfirmed | Ongoing |
Where Affected Users Stand Now and Exchange Safety Lessons
What Affected Users Can Realistically Expect
If you had funds on WazirX during the WazirX hack, your situation depends on which category you fall into. Users with balances in tokens that were not directly stolen may have partial access. Users whose holdings formed part of the hacked pool are holding recovery tokens with no fixed redemption date. A full, immediate refund looks unlikely in the near term.
India’s regulatory framework does not currently offer a deposit insurance scheme for crypto exchanges the way the DICGC covers bank deposits up to Rs5 lakh. SEBI has been moving toward a Virtual Digital Asset (VDA) regulatory framework, but formal exchange-level protections for retail investors are still being developed. You can check the current legal standing of crypto in India in our crypto legal status guide for 2026.
Tax Implications for Hack Victims
Indian tax law on hacked crypto is murky. Under current VDA tax rules, 30% tax applies to profits from crypto transfers, and 1% TDS applies to transactions above specified thresholds. Losses from theft are not explicitly deductible under current Income Tax Act provisions for VDAs. Affected users should consult a tax professional before filing, especially if they received recovery tokens, which may themselves be treated as a taxable asset upon receipt or redemption.
Practical Steps to Protect Your Funds Going Forward
The WazirX hack is a sharp reminder that exchange wallets are not personal wallets. When your crypto sits on an exchange, you do not hold the private keys. Here is what you can do right now:
- Move long-term holdings to a hardware (cold) wallet. Our hot wallet vs cold wallet comparison breaks down the trade-offs clearly.
- Only keep on exchanges what you are actively trading.
- Enable all available 2FA options on your exchange accounts.
- Spread holdings across more than one exchange; do not keep everything on a single platform.
- Regularly check whether your exchange has proof-of-reserves audits available.
Indian exchanges like CoinDCX, ZebPay, and Mudrex have each highlighted their own security measures after the WazirX incident. That does not mean they are immune to risk, but comparing security practices before choosing a platform is now a baseline expectation for any serious crypto investor.
Frequently Asked Questions
How did the WazirX hack happen step by step?
On 18 July 2024, attackers manipulated the transaction payload shown in WazirX’s Liminal custody interface so that authorised signers unknowingly approved a smart-contract call that transferred wallet ownership to the attacker. The attacker then upgraded the Safe wallet’s implementation contract, making the theft of approximately $234.9 million irreversible within minutes. Blockchain firm Elliptic identified on-chain patterns consistent with North Korea’s Lazarus Group.
Will WazirX users get their money back after the hack?
A full immediate refund is unlikely. WazirX’s restructuring plan offers affected users recovery tokens redeemable over time, tied to the exchange’s future revenue and any assets recovered from the attacker. Users who had unaffected balances may have partial withdrawal access. The timeline for full recovery token redemption has not been confirmed as of mid-2026.
What is the WazirX restructuring plan and recovery token?
The WazirX restructuring plan, filed under Singapore’s insolvency framework, proposes issuing recovery tokens to creditors instead of an immediate cash or crypto payout. These tokens represent a proportional claim on funds the exchange recovers or generates over a multi-year period. Creditor approval and court sanction are required for the plan to take effect.
Can WazirX hack victims claim a tax deduction in India?
Not under current rules. Indian VDA tax provisions do not explicitly allow deductions for theft losses. The 30% flat tax on crypto profits and 1% TDS framework does not account for hack-related losses. Recovery tokens received may also be treated as taxable assets. Affected users should consult a qualified tax professional before filing their returns.
Which Indian exchanges are considered safer after the WazirX hack?
No exchange is completely risk-free, and the WazirX hack proved that even multi-signature custody setups can be compromised. Indian exchanges like CoinDCX, ZebPay, and Mudrex operate under FIU-IND registration and have their own security protocols, but India does not yet have a formal investor protection fund for crypto. Storing significant holdings in a personal cold wallet remains the safest approach for long-term assets.
Next steps: Check your WazirX account for the latest withdrawal status directly on the platform. If you hold recovery tokens, monitor WazirX’s official blog and Singapore court announcements for redemption timelines. Consider moving idle holdings to a hardware wallet and reviewing your overall exchange exposure. Crypto carries significant risk of loss, and exchange hacks are a real and ongoing threat globally.
This is not financial advice. Data as of July 2026. Figures are sourced from Elliptic blockchain analysis reports and WazirX official announcements; verify against the latest official communications before citing.
Last updated: July 2026. Reviewed by the CryptoWire editorial team.