Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Crypto Oversight in the Spotlight After Warren Questions Federal Regulation

June 10, 2026

Bitcoin Obituaries Keep Coming—CZ Isn’t Buying It

June 10, 2026

UK mutual funds may soon be allowed to hold crypto ETNs, but only with a 10% leash

June 10, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Wallets and Exchanges»Liminal says infrastructure was not responsible for WazirX hack, blames compromised devices
Wallets and Exchanges

Liminal says infrastructure was not responsible for WazirX hack, blames compromised devices

July 20, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Multiparty computation (MPC) wallet provider Liminal said its infrastructure remains safe and was not compromised in the recent hack of India-based crypto exchange WazirX.

The firm made the statement in its post-mortem report on July 19. The report attributes the breach to compromised devices within WazirX’s network, clarifying that Liminal’s user interface (UI) was not responsible.

The exchange had earlier stated that the attack occurred due to a discrepancy between the data displayed on Liminal’s interface and the actual contents of the transactions. WazirX said its private keys were secured with hardware wallets.

Liminal’s post-mortem

According to Liminal, the July 18 breach, which resulted in an estimated $235 million loss, occurred because three of WazirX’s devices were compromised.

Liminal explained that its multi-signature wallet system was configured to provide a fourth signature if three valid signatures were received from WazirX. This setup allowed the attacker to exploit the compromised devices.

Liminal’s report detailed that the attack began when one of WazirX’s compromised devices initiated a legitimate transaction involving Gala Games tokens (GALA). Liminal’s server verified the transaction’s validity by issuing a “safeTxHash.” However, the attacker replaced this hash with an invalid one, causing the transaction to fail.

According to the firm:

“The fact that the attacker could alter the hash suggests that WazirX’s device was compromised before the transaction attempt.”

The report explained that the compromised devices at WazirX provided legitimate transaction details, which the attacker manipulated. In each of the three initial transactions, the attacker used different WazirX admin accounts, leading to transaction failures due to signature mismatches.

See also  Coinbase Terminates Its "Borrow" Service

The attacker then extracted the signatures from these failed transactions to initiate a new, fourth transaction, which was crafted to appear legitimate to Liminal’s system.

Because this fourth transaction used valid details and the nonce from a previously failed transaction, it was approved by Liminal’s server, resulting in the transfer of funds from the multisig wallet to the attacker’s Ethereum account.

Refuting WazirX claims

Liminal refuted the exchange’s claims that its servers caused incorrect information to be displayed, asserting that the compromised WazirX devices sent malicious payloads. The firm said:

“Given that three devices of the victim’s shared transactions sent out malicious payloads to Liminal’s server, we have reason to believe that the local machines were compromised.”

The MPC provider highlighted that its system automatically provides the final signature once the required number of valid signatures is received from the client.

In this instance, the transaction was authorized by three WazirX employees. The multisig wallet, as per the exchange’s configuration, was deployed and imported into Liminal’s system at WazirX’s request.

However, the post-mortem report leaves some critical questions unanswered, including how the attacker initially gained access to the three WazirX devices. Liminal suggested that a sophisticated man-in-the-middle (MIM) attack or similar client-side compromise is likely responsible.

WazirX said in its post-mortem that despite the use of robust security measures — including hardware wallets and a whitelist for destination addresses — the attacker managed to breach these defenses in a “force majeure event.”

The exchange has yet to publicly address the Liminal’s findings and did not respond to a request for comment as of press time. WazirX’s last update on the matter stated that it has reached out to law enforcement and is pursuing “additional legal actions.”

See also  Ostium Labs Adopts Chainlink for Cutting-Edge Crypto Trading Infrastructure

It added that the immediate plan of action is to trace the stolen funds and conduct a “deeper analysis” of the breach in concert with forensic experts to recover the customer funds.

Mentioned in this article

Source link

blames Compromised Devices Hack Infrastructure Liminal Responsible WazirX
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin Miner Kiln Infrastructure Raises $458M in Convertible Notes for Data Center Push

June 10, 2026

THORChain sets 11-step restart plan after $10.7M hack

June 10, 2026

Crypto’s killer app may be selling stocks after its own tokens failed retail

June 10, 2026

Lantronix and Cherry & White Launch Rapid Wi-Fi Platform That Brings Enterprise-Grade Connectivity to Critical Infrastructure in Minutes

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Blake3 Now Most Profitable PoW Algorithm for Crypto Miners, KAS Slips in Rankings

October 6, 2024

What Is Aster Chain and How the Protocol Plans to Expand Beyond BNB Chain

June 8, 2026

Federal Reserve will require state banks to get written ‘non-objection’ from central bank before engaging with stablecoins

August 9, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Crypto Oversight in the Spotlight After Warren Questions Federal Regulation

June 10, 2026

Bitcoin Obituaries Keep Coming—CZ Isn’t Buying It

June 10, 2026

UK mutual funds may soon be allowed to hold crypto ETNs, but only with a 10% leash

June 10, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$61,490.00-0.27%
  • ethereumEthereum(ETH)$1,621.23-1.05%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$586.26-1.11%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.10-3.60%
  • solanaSolana(SOL)$63.15-2.75%
  • tronTRON(TRX)$0.320724-0.55%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.79%
  • dogecoinDogecoin(DOGE)$0.082910-2.15%