The US Federal Bureau of Investigation (FBI) has reached out to Indian cryptocurrency exchange WazirX to investigate a cyberattack allegedly orchestrated by North Korean cybercriminals, industry insiders disclosed. This engagement aims to help the FBI future-proof its own cryptocurrency market against similar incidents.
Though WazirX has not officially disclosed the attackers’ identity, co-founder Nischal Shetty suggested the involvement of North Korea’s notorious Lazarus group. However, he did not confirm the FBI’s participation in the investigation.
On July 18, WazirX reported a breach of one of its multisig (multi-signature) wallets, leading to a loss exceeding $230 million—about 45% of investors’ funds. “This attack’s magnitude and sophistication are unprecedented for a centralized exchange,” Shetty remarked. He emphasized the involvement of a state actor, not a mere hacker, highlighting the breach’s extreme sophistication.
Blockchain experts also pointed to the possible involvement of the Lazarus group, known for executing some of the world’s largest crypto exchange heists, allegedly under the North Korean government’s backing.
To address the loss, WazirX proposed a “socialized loss strategy,” ensuring most investors receive 55% of their holdings, regardless of whether their assets were stolen. Investors who parked their funds in INR are eligible for 100% withdrawals, as INR was not part of the theft. Shetty declined to reveal the total INR amount held on the platform.
Investors expressed frustration over WazirX allowing trading to continue for three days post-attack, which caused major currencies like Bitcoin and Ethereum to drop by 10-15% on the exchange. Shetty defended this decision, stating the priority was to freeze leftover funds within 72 hours to prevent mass liquidation. “Despite the ongoing trading, only 0.1% of assets were sold, and prices did not experience a significant drop,” he explained.
An independent forensic audit report, expected within a week, will provide a clearer understanding of the attack’s nature and whether WazirX or its digital asset custody provider, Liminal, was responsible for any security lapses. WazirX’s multisig wallets, requiring multiple signatures to approve transactions, are managed through Liminal. Shetty called for Liminal to commission an external audit as well, noting the company’s silence and lack of an internal report.
Addressing the absence of insurance, Shetty stated, “Insurance for such a nascent industry in India is challenging…we don’t even have proper banking channels.”
On the prospects of fund recovery, Shetty highlighted the improvement in recovery rates due to advanced tools and global law enforcement expertise. According to the Web3 bug bounty platform Immunefi, nearly $74 million in stolen funds were recovered in seven cases during Q1 2024, accounting for over one-fifth of all losses that quarter.
“The recovery will take time—potentially 3 to 9 months,” Shetty said. “The outcome is uncertain, but maintaining honesty and transparency with stakeholders is crucial at this time.”

