{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:28.400Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"WazirX signers approved a spoofed transaction and lost $235M","date":"2024-07-18","date_precision":"day","victim_org":"WazirX","sector":"Cryptocurrency","country":"India","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":234900000,"loss_note":"Approximately $234.9 million in ETH and ERC-20 tokens at the value on July 18, 2024. WazirX and custody provider Liminal publicly disagreed over which side's systems were compromised.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), per multiple third-party analyses","summary":"Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.","how_it_worked":"The signers were the target, and the deception was in what their screens showed them. Analyses of the incident found a discrepancy between how the transaction was rendered in the Liminal custody interface and the actual payload being signed: signers reviewed what appeared to be a routine, whitelisted transfer while the underlying data authorised a malicious contract upgrade. Three WazirX signers and the Liminal signer approved it, satisfying the four-of-six threshold. Because the approval was cryptographically valid, address whitelisting, hardware wallet storage and the multisig scheme itself all passed cleanly, and the attacker gained control to drain the remaining balance without needing any further key.","lessons":"Signers need to verify transaction payloads on an independent, out-of-band device that renders the raw calldata, since any control that trusts the same interface the attacker can influence provides no assurance at all.","confidence":"Reported","sources":[{"title":"2024 WazirX hack","url":"https://en.wikipedia.org/wiki/2024_WazirX_hack","publisher":"Wikipedia"},{"title":"Explained: The WazirX Hack (July 2024)","url":"https://www.halborn.com/blog/post/explained-the-wazirx-hack-july-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-wazirx-signers-approved-a-spoofed-transaction-and-lost-235m"}]}