Cointime

Download App
iOS & Android

Bengal Man Arrested in Connection With $235 Million WazirX Hack

Cointime Official

From decrypt by Vismaya V

Delhi Police’s Intelligence Fusion and Strategic Operations (IFSO) division has arrested a man from West Bengal, in connection with a massive cyberattack on WazirX.

In July, the crypto industry witnessed the hack of India’s largest crypto exchange, WazirX. The exploit resulted in losses of approximately $235 million, with hackers targeting the platform’s hot and cold wallets.

The accused SK Mausad Alam is under custody for allegedly facilitating the WazirX heist by opening a fraudulent account on the exchange and selling it to a third party, which led to unauthorized access to the platform.

According to the chargesheet reviewed by Decrypt, Alam opened an account under the alias of Souvik Mondal and sold the credentials to someone called “M Hasan” via Telegram.

Delhi police disclosed how Alam was in contact with a "buyer of crypto accounts" who "offered him a good amount on getting crypto accounts of WazirX with credentials."

In return for selling his credentials, Alam reportedly received "08 USDT in his Binance account," per the chargesheet.

Police wrote in the chargesheet that during their investigation they found evidence that Alam had received crypto deposits worth $107,000 in the WazirX account created using his credentials.

The hackers’ modus operandi involved draining WazirX's hot wallet of GALA tokens to force the exchange to transfer additional assets from its cold wallet.

This tactic ultimately granted the perpetrators access to WazirX’s multisignature wallet, police said, leading to the siphoning of crypto worth millions.

The attack on WazirX was initially attributed to North Korea-based hacker group Lazarus by cybersecurity firm Elliptic.

In the course of the probe, authorities seized three laptops they say were used by WazirX’s authorized signatories to approve transactions. However, initial forensic analysis did not reveal any unauthorized access to these devices.

Despite the severity of the breach, investigators found no evidence of unauthorized access to WazirX's internal systems, confirming that the attack was carried out through external means.

The police stated WazirX cooperated fully with the authorities throughout the investigation, providing critical data such as KYC records and transaction logs.

Investigators said they faced challenges obtaining critical data from Liminal Custody, a third-party service provider responsible for securing the exchange’s cold wallets.

Following the hack, WazirX’s investigative report claimed the firm had “the malicious transaction was not sent to any of the destination addresses in the whitelisted addresses, which should have been prevented by Liminal.”

  Liminal told Decrypt at that time the multi-signature smart contract wallet used in the attack was allegedly “created independently and further imported on the Liminal platform.”

The investigation is ongoing, with authorities expected to file a supplementary chargesheet once additional information from entities like Telegram and Liminal Custody is obtained.

Liminal Custody did not immediately respond to a request for comment from Decrypt.

Comments

All Comments

Recommended for you

  • Fed's Collins: Another rate cut in December is under consideration, but not finalized

    Collins from the Federal Reserve stated: A rate cut in December is clearly being considered, but it has not been finally determined. There are currently no signs of price pressure. More data will be released before December, and we will have to continue to evaluate and interpret it reasonably. (Jinshi)

  • An entity called "7 Siblings" bought 1.06 million EIGEN in the past two days

    According to Onchain Lens monitoring, an entity named "7 Siblings" bought 1.06 million EIGEN in the past two days, with an average purchase price of $2.43,

  • 60 million WLDs transferred to Worldcoin multi-signature address, may be used for market making

    According to iChainfo's monitoring, 60 million WLD (worth $135.9 million) have been transferred to Worldcoin's multi-signature address. It is expected that these WLD will soon be transferred to several market makers.

  • Cryptocurrency stocks rise in pre-market trading

    influenced by the strong performance of Bitcoin, cryptocurrency concept stocks in the US market rose before the market opened. Coinbase (COIN.O) rose 2.1%, Bit Digital (BTBT.O) rose 2.8%, MicroStrategy (MSTR.O) rose 2.4%. ProShares Bitcoin Strategy ETF rose 2%, iShares Bitcoin Trust rose 2.2%.

  • U.S. Bitcoin ETFs Experience Third-Largest Outflow Since Launch

    On Thursday, U.S.-listed bitcoin exchange-traded funds experienced their third-largest outflow since launch, with over $400 million being drained. Interestingly, each time there has been an outflow greater than $400 million, a local bottom in price has been observed, as seen on May 1 and Nov. 4. This comes as stablecoin liquidity and bitcoin transactions are on the rise, while the ETH/BTC ratio has slid to its lowest point since April. Some are questioning whether bitcoin is losing its bullish momentum.

  • Crypto KOL him: He once transferred 20 million Fartcoins to the Truth Terminal wallet, now worth 5 million US dollars

    On November 15th, Equation Founder him posted on X that a whale had sent 20 million Fartcoins to Truth Terminal's wallet address, which was worth $40,000 at the time and is now worth $5 million, making Truth Terminal the first AI millionaire. Finally, he stated that the whale was himself.

  • How a popular crypto exchange empowers traders with customization and efficiency

    This crypto trading platform introduces unique features to the market that are designed to meet the fast-paced needs of users.

  • EU regulators set out guidelines on restrictions for cryptocurrency providers

    the European Banking Authority (EBA) is the European regulatory agency responsible for addressing weaknesses in the European banking industry. It has issued two sets of guidelines, including specific guidelines for payment service providers (PSPs) and cryptocurrency asset service providers (CASPs). On November 14th, EBA released guidelines that specify the measures that PSPs and CASPs must take when transferring funds or cryptocurrency to comply with EU and national restrictive measures. According to EBA, these guidelines ensure the implementation of EU and national sanctions. EBA believes that weaknesses in control, internal policies, and procedures may pose legal and reputational risks to financial institutions (including PSPs and CASPs). In addition, weak links in these areas for financial institutions may also "weaken" the effectiveness of the EU's restrictive measures system. The European Banking Authority emphasizes that this may lead to rule evasion, thereby affecting the stability of the EU's financial ecosystem. According to ECA, these guidelines will apply from December 30, 2025.

  • Dogecoin Leads the Pack—But These Dog Coins Are Running Up Gains Too

    Dogecoin may have a backer headed to the White House, but other big dog-themed coins are jumping on token listings and broader crypto hype.

  • SocGen FORGE to launch its EURCV stablecoin in XRP Ledger. Why?

    Societe Generale-FORGE (SG-FORGE) said it plans to launch its EURCV stablecoin on the XRP Ledger (XRPL) founded by Ripple.