Four Signers Approved a Transaction That Was Not What They Saw
India's largest crypto exchange required four of six signatures to move funds. It got them. The signers were looking at a custody interface that displayed one transaction while the blockchain received another, and the fake contract had been sitting there for eight days.

WazirX was India's largest cryptocurrency exchange, and it did the thing security people recommend. Its main wallet was multi-signature. Moving funds required four of six authorized signatories to approve, three from WazirX and one from Liminal, the custody provider whose interface the signers used. No single compromised person could drain it.
On July 18, 2024, four of them approved a transaction and about $234.9 million left anyway.
The attack worked on the gap between what a human sees and what a machine executes. The signers were reviewing transactions through Liminal's interface. The attacker exploited discrepancies between what that interface displayed and the actual transaction payload being signed, so that the approval each signer believed they were giving to a routine operation was in fact authorizing a transfer of control to an attacker-controlled smart contract. Four people looked at their screens, saw something reasonable, and signed something else.
The preparation is what elevates this from an exploit to an operation. The malicious smart contract had been deployed eight days before the attack, on July 10. The wallet configuration had been quietly rearranged in advance to avoid tripping detection. This was not somebody finding a bug and pulling the trigger the same afternoon. Somebody had been inside the process for over a week, setting the board.
The haul crossed more than 200 different cryptocurrencies, roughly 35,000 ETH among them. WazirX suspended all withdrawals immediately, which stopped further losses and simultaneously froze every ordinary user out of their own money.
Elliptic linked the attack to North Korea. The technique, the patience, and the targeting of a custody interface rather than the cryptography all fit the pattern.
What followed was the messiest aftermath in this section. WazirX's Singapore-based parent, Zettai Pte Ltd, secured a four-month moratorium from the Singapore High Court in August 2024 to restructure. In October, the co-founder of rival Indian exchange CoinSwitch publicly accused WazirX of transferring $75 million of user funds to Bybit and KuCoin in the wake of the attack; WazirX described the movements as rebalancing. In November, Indian law enforcement arrested a man in West Bengal who had allegedly sold his WazirX account credentials to the attackers, which is a genuine arrest connected to the case and also not remotely the person who executed it.
The compensation mechanism became Recovery Tokens: instruments representing each creditor's share of the stolen assets, to be bought back gradually out of future revenue. In practical terms users were asked to accept a claim on WazirX's future earnings in place of the crypto they had deposited. Withdrawals were projected to resume around April 2025, roughly nine months after the theft.
The lesson is uncomfortable for anyone who treats multisig as a solved problem. WazirX's four-of-six requirement functioned exactly as designed. Four authorized humans, using the approved tooling, gave genuine approvals. The cryptography never broke. What broke was the assumption that the thing on the screen is the thing being signed, and no number of additional signers fixes that, because every one of them is reading the same lying interface.
The Aftermath
WazirX's parent Zettai Pte Ltd obtained a Singapore court moratorium in August 2024 and restructured around Recovery Tokens, instruments giving creditors a claim on future revenue in place of their deposited crypto. Withdrawals were projected to resume around April 2025, roughly nine months after the theft. One arrest was made in West Bengal in November 2024, of a man alleged to have sold his account credentials to the attackers, not of anyone who executed the operation. Elliptic linked the attack to North Korea, which places the actual perpetrators beyond recovery. The stolen assets have not been returned.
COMMENTS