WazirX Hack Explained: What Happened, Who Did It & Where Is Users’ Money in 2026

wazirx hack

The Day India’s Crypto World Changed Forever

On the morning of July 18, 2024, millions of Indian crypto investors woke up to news that shook the entire country’s digital asset community.

WazirX — India’s largest cryptocurrency exchange, trusted by over 6.6 million Indians — had been hacked.

Not a small breach. Not a minor technical issue.

$234.9 million — gone. Stolen in a single, carefully orchestrated attack by one of the world’s most sophisticated cybercriminal organizations: North Korea’s Lazarus Group.

Within hours, WazirX suspended all withdrawals. Millions of Indian users found themselves locked out of their own funds. Some had their entire savings on the platform. Others had invested for years — watching their portfolios grow — only to find they could not access a single rupee.

This is the complete story of the WazirX hack — how it happened, who did it, what happened to the stolen money, and where things stand for affected users in 2026.

What is the Lazarus Group?

Before understanding how the WazirX hack happened, it is essential to understand who did it.

The Lazarus Group is a state-sponsored cybercriminal organization directly linked to the North Korean government — specifically to the Reconnaissance General Bureau, North Korea’s primary intelligence agency.

They are not ordinary hackers. They are one of the most sophisticated and well-funded cybercriminal operations in the world — with a decade-long track record of stealing billions of dollars from financial institutions, banks, and cryptocurrency exchanges worldwide.

Lazarus Group’s Greatest Hits

AttackYearAmount Stolen
Bangladesh Bank Heist2016$81 million
WannaCry Ransomware2017Global damage
Ronin Network (Axie Infinity)2022$625 million
Harmony Horizon Bridge2022$100 million
Atomic Wallet2023$100 million
WazirX2024$234.9 million

The US government, the United Nations, and multiple cybersecurity agencies have confirmed that Lazarus Group uses stolen crypto funds to finance North Korea’s weapons programs — including its nuclear missile development.

When WazirX was hacked, it was not just a business crisis. It was an attack by a nation-state actor.

How the Hack Happened — Technical Breakdown

The WazirX hack was not a random cyberattack. It was a meticulously planned, months-long operation that exploited a specific vulnerability in WazirX’s security architecture.

The Multi-Signature Wallet — The Weak Point

WazirX used a multi-signature (multi-sig) wallet system for storing user funds. Multi-sig wallets require multiple private keys to authorize a transaction — theoretically making them more secure than single-key wallets.

WazirX’s setup required 4 out of 6 signatures to authorize any large transaction:

  • 3 signatures from WazirX team members
  • 1 signature from Liminal Custody — WazirX’s third-party custody provider

On paper, this seemed secure. In practice, it had a fatal vulnerability.

Phase 1 — Social Engineering (Months Before the Hack)

Long before the actual theft, Lazarus Group began a sophisticated social engineering campaign targeting WazirX employees.

They created fake job profiles on LinkedIn, sent phishing emails, and used other deception techniques to gain initial access to WazirX’s internal systems.

Cybersecurity researchers later identified that the hackers had been inside WazirX’s systems for months before executing the final attack — studying the wallet architecture, understanding the signing process, and waiting for the perfect moment.

Phase 2 — Compromising the Signing Process

The actual attack exploited the gap between what WazirX’s team saw on their screens and what was actually being signed on the blockchain.

Using sophisticated malware, the hackers manipulated the transaction data at the moment of signing. WazirX signers believed they were approving a routine transaction — but they were actually approving a transaction that transferred control of the wallet to the attackers.

This type of attack is known as a “blind signing” exploit — where the user approves something without being able to verify exactly what they are approving.

Phase 3 — The $234.9 Million Theft (July 18, 2024)

On July 18, 2024, the attackers executed their plan.

In a series of rapid transactions, they drained WazirX’s Safe multisig wallet — stealing:

AssetStatus
SHIB (Shiba Inu)Largest portion stolen
ETH (Ethereum)Significant amount
MATIC (Polygon)Large amount
PEPESignificant amount
USDTVarious amounts
Other tokens200+ different assets
Total~$234.9 million

The entire operation took a matter of minutes. By the time WazirX’s team realized what had happened — it was too late.

Phase 4 — Laundering the Money

Within hours of the theft, the Lazarus Group began laundering the stolen funds through Tornado Cash — a cryptocurrency mixing service that obscures the origin of transactions by mixing them with other funds.

Blockchain analytics firms tracked the stolen assets being moved and sold across dozens of wallets — deliberately fragmented to make tracking and recovery as difficult as possible.

WazirX vs Liminal Custody — The Blame Game

One of the most controversial aspects of the WazirX hack was the immediate public dispute over who was responsible.

WazirX’s Position

WazirX claimed the hack occurred because Liminal Custody’s infrastructure was compromised — arguing that the malicious transaction was injected through Liminal’s interface, not through WazirX’s own systems.

Liminal Custody’s Position

Liminal Custody strongly denied any compromise of their systems — arguing that the vulnerability was in WazirX’s signing process and their own internal security practices.

What Investigators Found

Independent blockchain security firms including Mandiant (Google’s cybersecurity division) conducted forensic investigations. Their findings suggested the attack was highly sophisticated and likely involved compromising multiple points in the signing process.

The dispute between WazirX and Liminal Custody has never been fully resolved — adding to user frustration as both parties pointed fingers at each other while millions of Indians remained locked out of their funds.

Immediate Aftermath — Chaos and Confusion

The hours and days following the hack were chaotic for WazirX users.

July 18, 2024 — Hours After the Hack:

  • WazirX suspended all withdrawals, deposits, and trading
  • Users flooded social media with panic and anger
  • WazirX’s support team was immediately overwhelmed
  • CoinSwitch, CoinDCX, and other Indian exchanges saw massive inflows as users rushed to alternative platforms

WazirX’s Initial Response:

  • Filed complaints with Indian Police
  • Reported to Financial Intelligence Unit (FIU) India
  • Notified CERT-In (Computer Emergency Response Team India)
  • Reached out to over 500 exchanges worldwide to block attacker wallet addresses
  • Launched a $23 million bounty program — offering up to $10,000 in USDT for actionable intelligence leading to asset recovery

Binance’s Response: Binance — which had a disputed ownership relationship with WazirX — publicly distanced itself from the hack, denying responsibility for WazirX’s security practices.

The India-Singapore Jurisdiction Problem

Perhaps the most painful aspect of the WazirX hack for Indian users was discovering a fundamental truth about the exchange they had trusted:

WazirX’s parent company — Zettai Pte Ltd — is registered in Singapore, not India.

This single fact had enormous consequences:

  • When WazirX filed for restructuring, it went to Singapore’s High Court — not Indian courts
  • Indian users who filed petitions in Indian courts found their cases dismissed
  • India’s Supreme Court advised affected users to seek remedy through civil or foreign proceedings — effectively telling millions of Indian retail investors to navigate Singapore’s legal system
  • Most ordinary Indian investors had no practical ability to participate in Singapore legal proceedings — lacking resources, knowledge, and access

This situation sparked widespread outrage across India’s crypto community:

“An exchange that marketed itself as ‘India Ka Bitcoin Exchange’ — India’s Bitcoin Exchange — but when crisis hit, the legal fight happened 4,000 kilometres away in Singapore.”

The jurisdictional issue exposed a fundamental gap in India’s crypto regulatory framework — and demonstrated why clear domestic regulation for crypto exchanges is urgently needed.

The $70 Million CoinSwitch Fund

In a remarkable display of solidarity within India’s crypto community, CoinSwitch — one of WazirX’s direct competitors — announced a $70 million recovery fund for affected WazirX users in January 2025.

The “CoinSwitch Cares” initiative was described as one of the largest voluntary recovery efforts in Indian crypto history.

While the fund did not directly replace lost funds, it demonstrated:

  • The scale of the humanitarian impact of the hack
  • The maturity of India’s crypto industry in supporting affected users
  • The reputational damage WazirX’s hack caused across the entire Indian crypto ecosystem

The Singapore Court Battle — 16 Months of Waiting

After the hack, WazirX began a complex legal restructuring process through Singapore’s courts.

Key Legal Milestones

DateEvent
Aug 2024WazirX files for restructuring in Singapore
March 202593.1% of 140,000+ creditors vote YES on restructuring plan
June 2025Initial plan rejected — low creditor participation, procedural issues
October 2025Singapore High Court approves revised plan — 95.7% creditor vote
Oct 15, 2025Plan filed with Singapore’s ACRA
Oct 24, 2025WazirX RESUMES trading — 16 months after hack
Nov 202585% of funds distributed to eligible users
Jan 9, 2026Recovery Tokens issued to all eligible users
May 2026Futures trading launched — profits go to RT holders

The Madras High Court Ruling

In October 2025, the Madras High Court delivered an important ruling — affirming that customer assets like XRP could NOT be used to offset WazirX’s platform losses. This ruling protected Indian users’ assets from being absorbed into general recovery funds — a significant win for affected users.

What Happened to the Stolen Money?

This is the question every affected user wants answered.

The honest truth: Most of it is gone.

StatusDetail
Total stolen~$234.9 million
Amount traced~12–15%
Amount recoveredMinimal
Tornado Cash launderedSignificant portion
Still in Lazarus walletsUnknown amount

The Lazarus Group’s sophisticated laundering operation — using Tornado Cash, chain hopping, and hundreds of intermediate wallets — has made recovery extremely difficult.

International law enforcement agencies including the FBI and Interpol have been involved in tracking the stolen funds. But recovering crypto stolen by a state-sponsored hacking group supported by North Korea’s government is an extraordinarily complex challenge.

Recovery Status for Users — June 2026

Here is exactly where affected users stand as of June 2026:

What Was Returned

85% of approved claims — distributed in October-November 2025 through a combination of:

  • Crypto assets
  • Cash distributions
  • Stablecoin payments

Important Caveat — Rebalanced Values

Many users received less than expected — because payouts were calculated on rebalanced token values at a specific reference date — NOT the original July 2024 prices.

If a token crashed 60% after the hack, users received 85% of the post-crash value — meaning their actual recovery was far less than 85% of their original holdings.

Recovery Tokens (15% Remaining)

The remaining 15% was converted into Recovery Tokens (RTs):

FeatureDetail
Tradable?No — currently non-tradable
Buyback mechanismQuarterly — if $10M+ recovered
TimelineUp to 36 months
ValueDepends entirely on WazirX’s future profits
RiskIf WazirX fails — RTs become worthless

What Changed at WazirX After the Hack

WazirX implemented significant security changes:

Before HackAfter Hack
Multi-sig self-custody✅ BitGo institutional custody
No insurance✅ BitGo insurance coverage
No Proof of Reserves✅ Real-time PoR published
Limited oversight✅ Third-party oversight
Liminal Custody✅ Replaced by BitGo

Lessons — What the WazirX Hack Taught India

The WazirX hack was India’s most expensive crypto lesson. Here is what it taught:

1. “Not your keys, not your coins” The most fundamental rule of crypto — if you don’t hold your own private keys, you don’t truly own your crypto. Keeping large amounts on any exchange carries exchange-specific risk.

2. Check where an exchange is registered WazirX marketed itself as “India Ka Bitcoin Exchange” but was legally registered in Singapore. Always check the legal jurisdiction of any exchange you use.

3. Diversify across exchanges Never keep all your crypto on one exchange. If one exchange is hacked, you lose everything on that platform.

4. Custody matters more than brand WazirX was India’s most trusted exchange — and it was still hacked. Brand trust does not equal security. Always check custody arrangements.

5. India needs dedicated crypto regulation The jurisdictional confusion exposed by this hack — with Indian users forced to navigate Singapore courts — demonstrates the urgent need for India’s own dedicated cryptocurrency regulation.

FAQs — WazirX Hack 2024

How much was stolen in the WazirX hack?

Approximately $234.9 million was stolen in the WazirX hack on July 18, 2024 — making it one of the largest exchange hacks in history.

Who hacked WazirX?

The WazirX hack was carried out by North Korea’s Lazarus Group — a state-sponsored cybercriminal organization linked to North Korea’s Reconnaissance General Bureau.

Have users gotten their money back?

Approximately 85% of approved claims were returned to users in October-November 2025. The remaining 15% is held in non-tradable Recovery Tokens.

Why was the case in Singapore and not India?

WazirX’s parent company Zettai Pte Ltd is registered in Singapore — not India. When WazirX filed for restructuring, it went to Singapore’s High Court. Indian courts dismissed most Indian user petitions.

Was the stolen money recovered?

Only approximately 12-15% of the stolen funds have been traced. Most of the money was laundered through Tornado Cash and remains unrecovered.

Is WazirX still operating in 2026?

Yes. WazirX resumed trading on October 24, 2025 and launched futures trading in May 2026. The exchange is operational but still rebuilding trust.

What are Recovery Tokens?

Recovery Tokens (RTs) represent the remaining 15% of affected user funds. They are non-tradable and will generate value only if WazirX achieves quarterly profits above $10 million.

What was WazirX’s bounty program?

WazirX launched a $23 million bounty program offering up to $10,000 in USDT for actionable intelligence leading to recovery of stolen assets.

Who is the Lazarus Group?

The Lazarus Group is a North Korean state-sponsored hacking organization responsible for stealing billions of dollars from financial institutions worldwide — including the $625 million Ronin Network hack in 2022.

Conclusion

The WazirX hack of July 2024 will be remembered as the darkest day in Indian cryptocurrency history.

$234.9 million stolen by North Korean state hackers. 6.6 million users locked out of their funds for over a year. A legal battle fought in Singapore courts while millions of Indian investors waited helplessly. A recovery process that returned most — but not all — of what was lost.

The hack exposed critical vulnerabilities — in WazirX’s security architecture, in India’s crypto regulatory framework, and in the blind trust that millions of Indian investors had placed in a platform they believed was safe.

As of June 2026, most affected users have received 85% of their funds. Recovery Tokens hold the promise of recovering the remaining 15% — but that promise depends entirely on WazirX’s ability to rebuild its business.

The full story of the WazirX hack is not just about one exchange. It is a lesson for every crypto investor in India — and a powerful argument for why India urgently needs clear, comprehensive cryptocurrency regulation that protects its citizens.

Editorial Disclaimer: This article is based entirely on publicly available information collected from reputable news sources including Yahoo Finance, CryptoPotato, CryptoTimes, Business Today, Mudrex, and official court documents. CryptoEmotions does not have a personal account on WazirX and has not been personally affected by this hack. This article is for informational purposes only — not financial or legal advice.

For the complete WazirX Review 2026 — including current fees, features, and whether you should use WazirX today — read our detailed review here.

Leave a Reply