How a Six-Signer Wallet Was Quietly Hijacked for $235 Million at WazirX
India's largest crypto exchange, WazirX, lost approximately $235 million after attackers gained control of its Safe multisig wallet.
Blockchain security firm Cyvers flagged the incident almost immediately, spotting a cluster of suspicious transactions traced back to Tornado Cash funding. The firm tried reaching WazirX directly, but by then the attacker had already begun converting stolen assets to ETH and moving toward an exit.

About thirty minutes later, WazirX publicly acknowledged the breach and paused all withdrawals on the platform.
The loss pushes WazirX to seventh place on Rekt's leaderboard of largest crypto hacks, trailing only this year's largest incident to date, the $304 million DMM Bitcoin exploit from late May — another case where a centralized exchange's multisig setup was the point of failure.
01A Slow-Burn Setup
Far from a smash-and-grab, the operation appears to have been planned well in advance. Analysis shared by Mudit Gupta indicates the attackers ran small test transactions against WazirX's systems starting at least eight days before executing the main exploit.
The wallet in question required six signatories to approve transactions — five belonging to WazirX staff, and a sixth held by Liminal, the exchange's third-party custody provider. WazirX later confirmed this signer structure in its own preliminary incident report.
Rather than attempting a direct withdrawal, the attackers pursued a subtler goal: replacing the legitimate multisig contract with a malicious one they controlled. Doing so meant getting around two layers of defense — Ledger hardware wallets used by each signer, and a whitelist restricting where funds could be sent.
02Bypassing the Signers
Gupta's breakdown suggests the attackers had already obtained two of the four keys needed to authorize the change. To secure the remaining two approvals, they turned to signature phishing — presenting signers with what looked like an ordinary USDT transfer request to approve, captured on-chain here.
WazirX believes the deception also reached into Liminal's own interface, where a mismatch between what was displayed and what was actually being signed may have let the attackers swap in their real payload undetected.
In hindsight, there was a warning sign: shortly before the exploit, a genuine USDT transfer attempt failed — a detail nobody flagged at the time. In reality, two of the four signatures collected that day weren't approving a USDT transfer at all; they were authorizing the malicious contract upgrade.
03The Takeover
Combining the two compromised keys with the two phished approvals, the attackers pushed through the multisig upgrade, swapping in their own contract. Notably, one of the phished approvals belonged to Liminal — the party meant to serve as a final check on outgoing transactions — pointing to a serious gap in Liminal's own review process.
Once the upgrade went through, the attackers had unrestricted control of the wallet and began draining it.
04Tracing the Money
A separate investigation by ZachXBT mapped out the movement of funds in detail, spanning more than a week before the attack itself:
July 8
A ChangeNOW hot wallet sent two transactions to 0xC891b507A7c109179d38E2Cb4DE6CD8Dc70D2ad4:
Timing suggests these funds trace back to two Bitcoin transactions: 53795dd1...ac83b92 and ddfd1891...757e5b9.
Separately, address 0xc687 received 1 ETH from Tornado Cash (tx), matching a 1 ETH Tornado Cash deposit made nine hours earlier (tx).
July 9
Addresses 0xc687 and 0xc891 exchanged funds with each other — a move that may have undermined the privacy Tornado Cash was meant to provide (tx 1, tx 2).
July 10
Six separate 0.1 ETH deposits went from 0xc6873ce725229099caf5ac6078f30f48ec6c7e2e into Tornado Cash. The eventual main attack address, 0x6EeDF92Fb92Dd68a270c3205e96DCCc527728066, then received six matching 0.1 ETH withdrawals from Tornado Cash.

That address proceeded to run test transactions — in ETH, SHIB, and USDT — against the 0x09b multisig: an ETH transfer, a SHIB transfer, and a USDT transfer.
July 18 — the day of the attack
The exploit was carried out against the WazirX wallet, with 0x6EeDF92Fb92Dd68a270c3205e96DCCc527728066 used to trigger the malicious contract calls, and funds ultimately routed to 0x04b21735E93Fa3f8df70e2Da89e6922616891a88 for the drain itself.
Adding a further wrinkle to the case, ZachXBT claimed an Arkham Intelligence bounty after tracing one of the attacker's transactions to a KYC'd exchange deposit.
Taken together, the layered use of Tornado Cash, staged test transactions, and multiple intermediary addresses points to a level of operational planning well beyond what's typical in most exchange hacks. Gupta noted in his write-up that "it's a very methodical and organized attack, pointing towards DPRK as the hacker" — a claim that, as of this writing, remains unconfirmed.
05What It Means
A $235 million loss of this scale inevitably raises broader doubts about whether current multisig and custody arrangements are fit for purpose. Even layered protections — hardware signers, address whitelists, a dedicated custodian — proved insufficient once signers themselves became the weak link through phishing and, allegedly, direct key compromise.
Coming on the heels of DMM Bitcoin's own multisig-related loss just weeks earlier, the WazirX incident reinforces a pattern: sophisticated attackers, potentially state-linked, are increasingly targeting the human and procedural layer around custody rather than the underlying smart contracts. It leaves centralized exchanges facing renewed scrutiny over whether pooling user funds behind any multisig, however well-designed, is a model that can hold up against patient, well-resourced adversaries.
Get new scam files the moment we publish them — usually 2–3 emails a week.