Skip to content
Back to journal
WazirX1 Sep 2026

Indian Crypto Exchange Hacks, Leaks and Disputes: Five Dated Incidents

Five Indian crypto platform incidents from 2020 to 2025, each with a date, an amount, an outcome and two published sources.

RudraResearch note 7 min read
An open register book with five ruled rows, each row carrying two ink stamps in the right column, one black and one orange, except the bottom row which carries a single orange stamp beside an empty cell

The point

Five incidents make up the public record of India's retail crypto platforms since 2020. One data leak, one ownership dispute, two exchange hacks, and one arbitration still open.

Together they touch more than 279 million dollars in stolen or disputed funds. Every entry below carries a date, an amount, an outcome, and two independently checked sources. Nothing here is inferred.

Two sources for every entry, and no adjectives

An entry appears here only when two independently published outlets have reported it. A figure repeated everywhere still does not qualify on its own.

Each row carries facts and dates. Adjectives about any platform are left out on purpose. What a platform did, when it happened, how much moved, and what the outcome was, in that order. Where a source could not confirm something, this list says so.

Custody structure decides how much of this list applies to a given platform. Custody means who holds the keys that can move your coins. Before the timeline, it helps to know what custody promises, covered separately in is the crypto in your basket actually yours.

The timeline, 2020 to 2025

2020 to 2021: BuyUcoin's user database reaches a hacking forum

Indian exchange BuyUcoin's database was copied on three dates in 2020: June 1, July 14 and September 5. The files surfaced publicly on a hacking forum in January 2021.

Cybersecurity outlet BleepingComputer counted 161,487 leaked records. CoinGape, citing the same leak, put the number at roughly 3.25 lakh affected users.

The data included emails, phone numbers, encrypted passwords, KYC documents with PAN and passport numbers, bank account details and trade history.

BuyUcoin said user funds were unaffected, with most holdings in cold storage, which means wallets kept offline. It said it was investigating. No fine or enforcement action against the exchange over this leak turned up in the sources checked here.

A platform that cannot say what happened to your complaint has already failed a test covered in every platform's published grievance officer.

2019 to 2023: Binance announces it owns WazirX, then says it does not

Binance announced it had acquired Indian exchange WazirX in November 2019. WazirX's own executives spoke about the deal openly for years afterward.

That changed in August 2022. Indian enforcement officials raided WazirX's Mumbai office over money-laundering allegations tied to 16 fintech firms. The same week, Binance's CEO tweeted that Binance held no equity in Zanmai Labs, the entity that operates WazirX. Binance's original blog post was edited to say the 2019 deal was "limited to an agreement to purchase certain assets and intellectual property."

In January 2023, Binance sent WazirX a letter demanding it retract its ownership statements by month end, or lose Binance's wallet and technology services. Zanmai refused. It produced an internal email trail and a January 2020 document describing WazirX accounts held "for the sole benefit of Binance."

Binance ended the services anyway on 3 February 2023. WazirX moved its assets to its own multi-signature wallets and kept operating. The ownership question has never been settled by a court.

2024: WazirX loses 234.9 million dollars in India's largest crypto hack

On 18 July 2024, attackers altered the smart contract behind a multi-signature wallet WazirX held with its custody partner, Liminal. Such a wallet needs more than one key to approve a transfer.

They drained 234.9 million dollars in tokens, a figure widely rounded elsewhere to 235 million. The Lazarus Group, a North Korea-linked hacking operation, was later tied to the attack.

WazirX halted trading and withdrawals the same day, and reset user balances to the hour before the breach. WazirX blamed Liminal for the failure. Liminal rejected that account and pointed instead to weaknesses on WazirX's own side.

In October 2025, Singapore's High Court approved a restructuring scheme. Users with pre-hack balances get 85 percent of their value back upfront. The remaining 15 percent is paid through tradeable Recovery Tokens over two to three years. WazirX targeted a restart by the end of October 2025, under a new custodian, BitGo.

That restart is the practical version of the question in what happens to your basket if the platform shuts down. It took fifteen months, in public, to get an answer.

2024 to 2025: CoinSwitch goes to arbitration over frozen assets

CoinSwitch's broker entity, Bitcipher, held roughly 59.34 crore rupees in assets through broker accounts on WazirX. Those assets were frozen along with everything else after the July 2024 hack.

CoinSwitch took the dispute to arbitration. Tribunal orders in December 2024 and March 2025 directed Zanmai to post security of roughly 45.4 crore rupees against CoinSwitch's claim. The security could take the form of an escrow deposit or a bank guarantee.

Zanmai appealed. It argued that Binance was responsible for the platform's cybersecurity failures under their 2019 arrangement. The Bombay High Court dismissed that appeal on 7 October 2025. Justice Somasekhar Sundaresan ruled that Zanmai's own broker agreement with CoinSwitch carried operational obligations it could not shift onto a third party.

A compliance review followed, set for 11 November 2025, and no source checked here reports what happened at it.

Zanmai's defense is exactly what reading what a platform actually publishes is built to test. The court decided the case on what Zanmai's own agreement said.

2025: an internal CoinDCX wallet is drained of 44.2 million dollars

On 19 July 2025, CoinDCX's CEO disclosed that an internal operational wallet had been drained of 44.2 million dollars. The wallet was used only to supply liquidity on a partner exchange, and was held separately from customer wallets.

Security firm Halborn's independent review put the figure slightly higher, at 44.3 million dollars. Halborn also found that outside researchers had flagged the breach roughly 17 hours before CoinDCX made it public.

Customer funds sat in segregated cold storage and were not touched. CoinDCX covered the full loss from its own treasury reserves. It offered a recovery bounty of up to 25 percent of any funds traced and returned, and worked with India's CERT-In on the investigation.

A treasury absorbing a loss is a different claim from a treasury proving what it holds. That distinction is covered in how to read a proof-of-reserves attestation.

Four questions this record tells you to ask

Read together, these five events show what typically happens after an exchange is hacked. They point at the same four questions, worth asking before you move money onto any platform.

Does the platform separate its operational funds from customer funds, and say so in writing before anything goes wrong?

Has it published its own dated incident report, or did the date only surface later, from a researcher or a court filing?

Does its custody arrangement name a specific partner and a specific signing structure?

And if two parties end up disputing something, is there an independent body that will rule on it? Without one, the argument stays public and unfinished, the way WazirX's ownership still is.

None of these questions has a universal right answer. They are the ones this record shows are worth asking. The answer to each is usually written down somewhere, the way a proof-of-reserves statement is written down, if you know to go looking for it.

Frequently asked questions

Has an Indian crypto exchange ever been hacked?

Yes. WazirX lost 234.9 million dollars on 18 July 2024, and CoinDCX lost 44.2 million dollars on 19 July 2025. Both exchanges confirmed the losses themselves, and both were reviewed independently by the security firm Halborn.

Did WazirX users get their money back after the 2024 hack?

Singapore's High Court approved a restructuring plan in October 2025. Users with pre-hack balances receive 85 percent of their balance value upfront. The remaining 15 percent is paid out through tradeable Recovery Tokens over two to three years.

Were customer funds touched in the CoinDCX hack?

No. CoinDCX has said the 44.2 million dollars came from an internal operational wallet, used to supply liquidity on a partner exchange. That wallet was held separately from the cold storage that holds customer funds. The company covered the loss from its own treasury.

What happened to BuyUcoin after its 2021 data breach?

BuyUcoin said user funds were unaffected and that it was investigating the leak. The sources checked here found no fine or enforcement action against the exchange over it in the years since.

Who actually owns WazirX, Binance or its Indian founders?

The question remains formally unresolved. Binance announced an acquisition in 2019, distanced itself from ownership in 2022, and ended its wallet and technology services to WazirX in February 2023. No court has ruled on the underlying ownership claim.

Crypto investments are subject to market risk. Not financial advice.

“A better allocation begins with a better explanation.”

Qatobit principle

Published construction. Fixed cadence. Versioned control.