WarizX Hacked for $235 Million, Be Aware: Tokens Are Being Sold Off
On July 18, according to Lookonchain monitoring, the wallet address 0x04b21735E93Fa3f8df70e2Da89e6922616891a88 of the Indian cryptocurrency exchange WazirX transferred assets worth over $235 million abnormally. The stolen assets are as follows: Subsequently, WazirX posted a statement indicating that a security vulnerability had occurred in one of their multi-signature wallets. The team is actively investigating the issue and has temporarily suspended INR and cryptocurrency withdrawals. Beosin Alert stated that the attacker obtained the signature data of the exchanges multi-sign wallet administrators and modified the wallets logic contract to execute erroneous logic, thereby stealing assets. Attacker address: 0x6eedf92fb92dd68a270c3205e96dccc527728066 Victim address: 0x27fd43babfbe83a81d14665b1a6fb8030a60c9b4 Based on the attackers behavior, it is speculated that the reason is the leakage of the administrators private key for the multi-signature wallet. Beosin provides a brief analysis of the attack reason as follows:The attacker deployed an attack contract: 0x27fd43babfbe83a81d14665b1a6fb8030a60c9b4. The function of this contract is to extract the token assets specified by the contract.The attacker obtained the signature data of the WazirX multi-sign wallet administrators and modified the wallets logic contract to the pre-deployed attack contract. The corresponding transaction is: https://etherscan.io/tx/0x48164d3adbab78c2cb9876f6e17f88e321097fcd14cadd57556866e4ef3e185dThe attacker submitted a token extraction transaction to the WazirX multi-sign wallet. Due to the proxy mechanism, the wallet contract used delegatecall to call the relevant