Fun

$235M WazirX exchange hack has implications for India’s crypto industry

News Feed - 2024-07-22 10:07:00

Shiraz Jagati10 hours ago$235M WazirX exchange hack has implications for India’s crypto industryNorth Korean hackers are suspected to be involved in the $235 million hack of Indian cryptocurrency exchange WazirX.6585 Total views7 Total sharesListen to article 0:00Follow upOwn this piece of crypto historyCollect this article as NFTJoin us on social networksThe massive $235 million hack on the Indian cryptocurrency exchange WazirX on July 18 has raised serious questions about exchange security and the future of cryptocurrency in India. 


The attack unfolded with alarming speed and precision, with Web3 security firm Cyvers being among the first firms to detect “multiple suspicious transactions” involving WazirX’s “Safe Multisig” wallet on Ethereum.Source: Cyvers Alerts


The attacker was able to move a staggering $234.9 million worth of funds to a new address, with each transaction’s caller being funded with assets from cryptocurrency mixer Tornado Cash.


The stolen funds consisted of a diverse selection of cryptocurrencies, including Tether (USDT), Pepe (PEPE) and Gala (GALA), with the attacker swiftly converting these assets into Ether (ETH) in an attempt to obfuscate the trail of stolen funds.


The exchange’s wallet also contained approximately $100 million in Shiba Inu (SHIB), $52 million in ETH, $11 million in Polygon’s (MATIC) and smaller amounts of other tokens.


In response to the security breach, WazirX immediately suspended withdrawals of both cryptocurrencies and Indian rupees on the platform. The exchange further announced that it was “actively investigating the incident.”


When asked to comment on the situation, Rajagopal Menon, a spokesperson for WazirX, told Cointelegraph: “We can’t speak to the press right now. You can get updates from our Twitter handle.”The future of India’s crypto sector


The hack could have major implications for India’s cryptocurrency sector, which has flourished despite government pressure.


Utkarsh Tiwari, the chief strategy officer for Indian cryptocurrency exchange KoinBX, told Cointelegraph that a security breach of this magnitude is bound to cause concern as it affects multiple stakeholders in the crypto ecosystem, including retail investors and other exchanges. He added:“Under India’s G20 presidency, we have seen our government push for comprehensive and standardized regulations for all global Virtual Assets Service Providers. Furthermore, historically, we have seen the Indian government always prioritize investor protection above all else.”


As a result, Tiwari predicts that Indian digital asset exchanges are likely to invest more heavily in advanced security infrastructure, something he believes can help showcase the resilience and innovation of the Indian digital asset market and community.


India’s crypto industry is anticipating potential relief from the country’s stringent crypto tax regulations.


Recent: Elon Musk lashes out at EU over ‘illegal’ free speech deal


India Finance Minister Nirmala Sitharaman will present the Union Budget for the next fiscal year on July 23, and the crypto sector hopes for favorable changes.


Since 2022, India has imposed one of the world’s most severe tax regimes on cryptocurrency, with a flat 30% capital gains tax on profits from digital assets, including non-fungible tokens. Additionally, a 1% tax deducted at source (TDS) is also levied on crypto transactions.


Sumit Gupta, CEO of Indian exchange CoinDCX, has been advocating for a reduction in the TDS rate to 0.01% in the forthcoming budget since these tax measures have significantly impacted Indian crypto exchanges.How did the attackers gain access to WazirX?


Meir Dolev, co-founder and chief technology officer of Web3 security firm Cyvers, told Cointelegraph that while the exploited vulnerability remains unknown, several key facts have emerged since the event.


First, he noted that WazirX uses a multisig wallet that requires four signatures to execute a transaction. The exchange also uses Liminal as a custody provider, which provides the last signature on every transaction. Lastly, WazirX’s wallet has a whitelist policy, with only a few wallets it can send funds to.


Dolev outlined the attack vector: “The attacker used two different addresses, the one that initiated the transaction and the second that received the funds. The one that initiated the transaction needed to pay gas fees so he funded his wallet via Tornado Cash.”“Eight days before the attack, the hacker also deployed a malicious contract that was later used to change the implementation of the WazirX wallet.”


He further explained that just a few minutes before the first exploit transaction, the attacker managed to change the implementation of their multisig wallet to his malicious contract by using the signatures of WazirX and Liminal custody. “From that moment, he could execute any transaction without needing WazirX or Liminal to sign on the transaction,” he highlighted.


Dolev speculated that the attacker likely compromised WazirX endpoints or laptops to gain the necessary signatures, possibly employing a user interface (UI) hijack on Liminal’s side.


He stated that WazirX might have thought they were going to sign on a legitimate transaction, and this is what it saw in the UI, which was possibly controlled by the hacker.


Liminal Custody has insisted that its platform remains secure, with its preliminary investigations showing that one of the self-custody multisig smart contract wallets created outside of the Liminal ecosystem was compromised: “We can confirm that Liminal’s platform is not breached, and Liminal’s infrastructure, wallets, and assets continue to remain safe.”North Korean involvement suspected


A number of analysts believe that North Korean hackers may be responsible for the incident, adding a layer of geopolitical intrigue to an already complex situation.


Blockchain forensics firm Elliptic previously told Cointelegraph that data pointed toward North Korean involvement, explaining, “The North Korea attribution is based on analysis of the onchain transactional behavior and other information. There are certain patterns and techniques that are characteristic of this type of actor.”


This sentiment was echoed by ZachXBT, who said the hack has the potential markings of a Lazarus Group attack — an infamous North Korean criminal organization with a long history of cybercrime.


Since 2017, Lazarus has terrorized the crypto space and is believed to be behind some of the industry’s biggest exploits, including the $600 million Ronin Bridge incident.


Moreover, in the wake of the hack, the cryptocurrency market experienced significant turbulence. Over $100 million worth of SHIB tokens were taken during the hack, causing the price of the popular memecoin to plummet by 10%.Seven-day SHIB price chart. Source: CoinMarketCap


Blockchain analysis platform Lookonchain reported on July 19, one day after the hack, that the attackers had already begun swapping SHIB assets for ETH, selling 35 billion SHIB tokens worth $618,000. At the time, theexploiter had exchanged most of the assets for 43,800 ETH ($149.46 million) and held a total of 59,097 ETH ($201.67 million). 


Recent: Airdrop token prices are crashing — Does Web3 need a new model?


WazirX has taken swift action to mitigate the damage and recover stolen funds. The exchange has filed an official police complaint and is pursuing additional legal actions.


It has reported the incident to the Financial Intelligence Unit and the Indian Computer Emergency Response Team and is contacting over 500 exchanges to block the identified addresses.


The exchange stated, “Many exchanges are cooperating with us, and we are actively working with them on additional resources to aid our recovery efforts.”# Bitcoin Wallet# Asia# Business# Wallet# India# Cryptocurrency Exchange# ExchangesAdd reaction

News Feed

Sen. Lummis proposes US government purchase 5% of total Bitcoin supply
Ciaran Lyons1 hour agoSen. Lummis proposes US government purchase 5% of total Bitcoin supplyThe pro-crypto Senator introduced the Bitcoin Reserve Bill while declaring "this is the solution, this is the answer, this
David Attlee14 hours agoSingapore High Court rules crypto personal property, compares it to fiat moneyThe judge didn’t see any difference between crypto, fiat money or shells as long as all those objects, physical or n
Decentralized Crowd Funding Platform Rocket Launchpad Launches in the Tezos Ecosystem
Decentralized Crowd Funding Platform Rocket Launchpad Launches in the Tezos Ecosystem press release Press Release:Rocket Launchpad is launching a Tezos-based IDO
Turner Wright6 hours agoPro-crypto lawmaker Tom Emmer wins Republican nomination for House speakerIt’s unclear if Emmer will have enough support to win in a full floor vote, but the lack of a speaker of the House has e
Ukraine Blocks Crypto Wallet Used to Raise Funds for Russian Forces
Ukraine Blocks Crypto Wallet Used to Raise Funds for Russian Forces The law enforcement and counter-intelligence agency of Ukraine has managed to seize the funds in a cryptocurrenc
Privacy-Centric Crypto Mixing Protocol Tornado.cash Plans to Deploy on L2 Platform Arbitrum
Privacy-Centric Crypto Mixing Protocol Tornado.cash Plans to Deploy on L2 Platform Arbitrum One of the largest cryptocurrency mixing protocols, Tornado.cash, has announced the proj
Galaxy Digital to Launch 2 New Bitcoin Funds in November
Galaxy Digital Asset Management, a division of the merchant bank Galaxy Digital, is launching two bitcoin funds in November, according to a source with direct knowledge of the matter.
Southeast Asia’s Largest Bank DBS Unveils Plan to Expand Crypto Services in Hong Kong
Southeast Asia"s Largest Bank DBS Unveils Plan to Expand Crypto Services in Hong Kong DBS, the largest bank in Southeast Asia, has unveiled its plan to expand its crypto services i
European Union to Put a 10,000-Euro Limit on Cash Payments; Transactions Over €1,000 in Crypto Will Be Scrutinized
European Union to Put a 10,000-Euro Limit on Cash Payments; Transactions Over €1,000 in Crypto Will Be Scrutinized The states of the European Union have convened to establish a n
Coinbase Commerce Now Supports Dogecoin Payments
Coinbase Commerce Now Supports Dogecoin Payments Coinbase now accepts commerce payments in dogecoin. With the addition of the meme crypto, Coinbase Commerce now
IMF Warns of Tough Year Ahead for World Economy Citing Slowdown in US, EU, China
IMF Warns of Tough Year Ahead for World Economy Citing Slowdown in US, EU, China The International Monetary Fund (IMF) has warned that 2023 will be a tougher year for most of the w
Turner Wright11 hours agoRecovery firm proposes cracking former Ripple CTO’s $244M Bitcoin hard driveStefan Thomas, the former chief technology officer at Ripple, has an IronKey hard drive containing 7,002 BTC with onl