Indian crypto platform WazirX confirms $230 million stolen during cyberattack

Avatar

At least $230 million worth of cryptocurrency was stolen from an India-based cryptocurrency platform named WazirX on Wednesday night.

Several blockchain security firms and researchers saw millions in digital coins flowing out of the platform before the company acknowledged a security breach. 

“Our team is actively investigating the incident,” the company said in a message posted to social media on Thursday morning. In an effort to keep the remaining assets safe, the platform shut down all withdrawals. 

The company did not respond to requests for comment about what will be done to repay customers who suffered losses. But in a second statement on Thursday afternoon, WazirX said a preliminary investigation found that the losses exceeded $230 million.

WazirX said that despite their efforts to protect customer assets, the attackers “appear to have breached” their security features before the theft occurred. 

“This is a force majeure event beyond our control, but we are leaving no stone unturned to locate and recover the funds. We have already blocked a few deposits and reached out to concerned wallets for recovery,” the company said. 

In June, the company reported that it had about $500 million in reserves. 

Founded in 2017, the platform is one of the largest cryptocurrency exchanges in India, allowing people to buy, sell and trade digital assets. The company was reportedly purchased by Binance in 2019 but the two sides later clarified in 2022 that the crypto giant only intended “to purchase certain assets and intellectual property of WazirX.”

On Wednesday night, blockchain security companies including Elliptic, Arkham and BlockSec said there was clear evidence of millions worth of cryptocurrency being siphoned out of WazirX. 

Elliptic pegged the losses at $235 million and broke down the currencies stolen, which include ETH, some U.S. dollar-pegged stablecoins and more. 

The attackers have “already swapped a number of these tokens for Ether using a variety of decentralized services,” according to Elliptic, which attributed the incident to hackers affiliated with North Korea based on blockchain data and other information reviewed by the company. 

Another prominent crypto hack researcher said the attack “has the potential markings of a Lazarus Group attack” — referencing a prominent North Korean hacking group known for headline-grabbing crypto platform thefts. 

Experts at the United Nations are investigating 58 cyberattacks on cryptocurrency firms allegedly conducted by North Korean hackers that allowed attackers to rake in about $3 billion over a six-year span. 

Cybercriminals and nation-states continue to exploit vulnerabilities in crypto platforms enabling large-scale heists. Just this week, another popular crypto platform saw about $8 million stolen and last month more than $300 million worth of Bitcoin was stolen from Japanese cryptocurrency exchange DMM Bitcoin.

CybercrimeNewsNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

New hacker group uses open-source tools to spy on entities in Asia-Pacific region

Next Post

Judge tosses out most of SEC cybersecurity case against SolarWinds

Related Posts

FBI and CISA Warn of BlackSuit Ransomware That Demands Up to $500 Million

The ransomware strain known as BlackSuit has demanded as much as $500 million in ransoms to date, with one individual ransom demand hitting $60 million. That's according to an updated advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI). "BlackSuit actors have exhibited a willingness to negotiate payment amounts," the
Avatar
Read More

CapraRAT Spyware Disguised as Popular Apps Threatens Android Users

The threat actor known as Transparent Tribe has continued to unleash malware-laced Android apps as part of a social engineering campaign to target individuals of interest. "These APKs continue the group's trend of embedding spyware into curated video browsing applications, with a new expansion targeting mobile gamers, weapons enthusiasts, and TikTok fans," SentinelOne security researcher Alex
Avatar
Read More