Indian crypto exchange Wazirx has announced a security breach affecting one of its multisig wallets, resulting in the theft of over $230 million. On July 18, the platform immediately paused both INR and cryptocurrency withdrawals as the team launched an investigation. The incident has sent shockwaves through the local crypto community, with many users demanding refunds and transparent communication.
Sophisticated Attack: Test Transactions and Lazarus Group Suspicions
Blockchain investigator Zachxbt traced the stolen funds back to a series of test transactions conducted on July 10, using SHIB tokens and deposits from Tornado Cash. The attackers upgraded the multisig contract to a malicious version, bypassing all signature requirements. Zachxbt stated: “The BTC appears to come from an unknown service making it difficult to trace. All I can say is the Wazirx hack has the potential markings of a Lazarus Group attack (yet again).” He also revealed he solved an Arkham bounty by identifying a KYC exchange deposit from the hacker, though such accounts are easily purchased online.
Security Researcher: Attackers Practiced for 8 Days
Mudit Gupta, a respected blockchain security researcher, provided further analysis. “The hackers started practicing the hack onchain at least 8 days ago and finally executed it today,” he wrote. He described the incident as “a very methodical and organized attack, pointing towards DPRK as the hacker.” Gupta explained that the attackers likely compromised two of the four private keys directly, while the remaining two were stolen through UI or wallet signature phishing. He suspects a wallet custody provider compromise.
Market Impact and User Concerns
Following the announcement, Wazirx's social media channels were flooded with panicked users unable to access their funds. The exchange has not provided a timeline for resuming withdrawals, only stating it is cooperating with law enforcement and third-party security teams. The hack reignites debates about India's crypto regulatory environment, as the Reserve Bank of India has long been skeptical of digital assets. On-chain data shows hackers are moving funds through mixers and cross-chain bridges, making recovery highly unlikely.
Lessons for the Industry
Security experts are urging exchanges to enhance multisig wallet management, including using hardware security modules and conducting regular audits. The Wazirx breach demonstrates that traditional multisig setups are not foolproof when private keys can be compromised through multiple attack vectors. The exchange has yet to announce any compensation plan for affected users.

