Skip to content
Incident record

WazirX Multisig Compromise, July 2024: What Happened & What to Check

Approximately $234.9m was taken from a WazirX multi-signature wallet held under a third-party custody arrangement.

Contained Discovered Disclosed
Share X in @
Schematic of the WazirX incident showing the key compromise stage as the failure point.
Schematic of the WazirX incident showing the key compromise stage as the failure point.

At a glance

AFFECTED ENTITY
WazirX
CHAIN(S)
Ethereum
REPORTED LOSS
approx. US$234.9 million(WazirX, 18 Jul 2024)
OFFICIAL RESPONSE
wazirx.com

Shared custody, shared blind spot

The WazirX wallet required signatures from multiple parties, including an external custodian. That arrangement is intended to ensure no single compromised organisation can move funds alone.

It does not help if every signer is looking at the same misrepresentation. WazirX described a discrepancy between what the signing interface displayed and the payload that was actually signed. Where that is the failure, adding signers adds people who approve the same wrong thing.

Why this pattern keeps appearing

This tracker contains more than one incident of this shape. The common thread is that the industry has invested heavily in protecting key material and comparatively little in guaranteeing the integrity of the approval step. Independent decoding of the raw payload, on separate infrastructure from the one proposing the transaction, is the control that addresses it.

Status

Conisec records this as Contained rather than Resolved. The immediate vector is closed, but customer recovery has proceeded through a court-supervised restructuring rather than a straightforward reimbursement, and the position of individual customers has not concluded in the way “Resolved” implies. Our status definitions are set out in the methodology.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Unauthorised transfers are executed from a WazirX multi-signature wallet. WazirX confirms the incident and suspends withdrawals. WazirX

What to check

WazirX published statements on its own blog and status channels; those, together with the subsequent court filings in the restructuring, are the authoritative record for customer impact.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. WazirX, Cyber attack on WazirX and its impact (18 Jul 2024)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.