WazirX
2024-07-18 • Rekt •
WazirX lost about $235 million after attackers took control of its Safe multisig wallet and drained funds to a main attack address. The source says the operators prepared with small test transactions, likely compromised two private keys, and phished two additional signatures by making signers believe they were approving a normal USDT transfer rather than a malicious Safe upgrade. ZachXBT traced funding through ChangeNOW and Tornado Cash, while Mudit Gupta assessed the operation as methodical enough to point toward DPRK involvement. The article treats that attribution as unconfirmed, so the incident should be tracked as a sophisticated crypto theft with possible, not proven, North Korean links.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 53795dd1629026c2f92a87d5cd24477… | 2024-07-18 | 2024-07-18 |
| HASH | ddfd189125ce88c622ec2453b2e9f2d… | 2024-07-18 | 2024-07-18 |