We review vendors based on rigorous testing and research but also take into account your feedback and our affiliate commission with providers. Some providers are owned by our parent company.
Learn more
vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.
Advertising Disclosure

vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.

WazirX Halts Withdrawals After Losing $230 Million in Hack

WazirX Halts Withdrawals After Losing $230 Million in Hack
Hendrik Human Published on 19th July 2024 Cybersecurity Researcher

Prominent Indian cryptocurrency exchange WazirX suspended withdrawals on Thursday following a security breach that resulted in the loss of $230 million, approximately half its reserves. The breach, which WazirX described as a “force majeure event,” involved the compromise of one of its multisig wallets.

The Mumbai-based firm revealed that the compromised wallet required six signatories for authentication, five of whom were part of the WazirX team. The security incident was attributed to a discrepancy between data displayed on Liminal’s interface and the actual transaction contents.

In a statement, WazirX said, "At WazirX, our commitment to transparency and community welfare is paramount. There was a cyber attack on one of our multisig wallets. Below are the preliminary findings to clarify the situation:"

They continued, "A cyber attack occurred in one of our multisig wallets involving a loss of funds exceeding $230 million. This wallet was operated utilizing the services of Liminal's digital asset custody and wallet infrastructure from February 2023." WazirX elaborated on the mechanics of the breach, noting, "The wallet had six signatories—five from our WazirX team and one from Liminal, who were responsible for transaction verifications."

According to TechCrunch, Liminal, a wallet infrastructure provider, stated that the compromised wallet had been created outside its ecosystem. According to WazirX, during the attack, the payload was replaced, transferring control of the wallet to the attacker.

Blockchain explorer Lookchain reported that the breach involved the theft of over 200 cryptocurrencies, including:

  • 5.43 billion SHIB tokens
  • 15,200 Ethereum tokens
  • 20.5 million Matic tokens
  • 640 billion Pepe tokens
  • 5.79 million USDT
  • 135 million Gala tokens

Blockchain data indicates that the attackers are attempting to offload these assets using the decentralized exchange Uniswap. Risk management platform Elliptic suggested that the hackers have affiliation with North Korea.

The loss of $230 million is a severe blow to WazirX, which disclosed holdings of approximately $500 million in its June proof-of-reserves report. In response to the incident, CoinSwitch and CoinDCX, two other leading Indian crypto exchanges, reassured their users that their funds were secure and unaffected.

CoinDCX CEO Sumit Gupta emphasized the robustness of their wallet security, while CoinSwitch CEO Ashish Singhal advised caution during trading due to potential market volatility.

In more bad news for the financial sector, Prudential recently revised its assessment of a February cyberattack, revealing that the personal information of 2.5 million customers were stolen — a far cry from the initially reported 36,000.

About the Author

Hendrik is a writer at vpnMentor, specializing in VPN comparisons and user guides. With 5+ years of experience as a tech and cybersecurity writer, plus a background in corporate IT, he brings a variety of perspectives to test VPN services and analyze how they address the needs of different users.

Please, comment on how to improve this article. Your feedback matters!

Leave a comment

Sorry, links are not allowed in this field!

Name should contain at least 3 letters

The field content should not exceed 80 letters

Sorry, links are not allowed in this field!

Please enter a valid email address