In a significant cybersecurity incident on July 18, 2024, WazirX, a prominent Indian cryptocurrency exchange, fell victim to a wallet exploit resulting in the unauthorized transfer of more than $230 million worth of crypto assets. The attack, which targeted the exchange’s multisig wallet on the Ethereum network, has sent shockwaves through the crypto community and led to substantial market volatility for affected tokens.
According to The Block’s report, security firm Blocksec says the exploit likely stemmed from a private key compromise. The attacker managed to upgrade the implementation of the Safe Wallet to a malicious contract, enabling them to drain the funds. Yajin Zhou, co-founder of Blocksec, explained that the leaked private keys were used to upgrade a safe multi-sig wallet holding a large number of assets to a malicious contract, which was then used to drain most of the assets in the Safe Wallet.
WazirX has acknowledged the security breach and has temporarily paused all withdrawals, including both cryptocurrency and Indian Rupee (INR), as they investigate the incident. The exchange stated that their team is actively working to understand and address the situation.
cryptoglobe.com