A Singapore court has allowed Zettai Pte Ltd, the parent entity tied to crypto exchange WazirX, to hold an online creditors’ meeting on a restructuring plan aimed at recovering more than $230 million stolen in a July 2024 cyberattack. The High Court also granted a 16-week moratorium and approved changes to streamline the voting process, while saying there was no proper evidence for claims that Zettai had orchestrated the theft. WazirX said the proposed scheme would reorganize liabilities, issue recovery tokens, and potentially restart the platform with new products including a decentralized exchange; if creditors and the court approve it, initial payouts could begin within 10 business days after the plan takes effect.
The recovery effort follows a July 18 breach of a multi-signature wallet that forced WazirX to halt rupee and crypto withdrawals and later revealed losses affecting roughly 45% of exchange assets. WazirX and custody provider Liminal publicly disputed responsibility for the exploit, while users criticized the exchange’s transparency, withdrawal freezes, and an earlier "socialised loss" proposal that would have returned only 55% of tokens immediately. The company has reported the incident to police, launched bounty efforts, said it had frozen an initial $3 million tranche of stolen assets, and disclosed liquid assets of 566.38 million USDT against 546.47 million USDT in claims as legal and customer pressure continues to mount.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-09, the Singapore High Court authorized Zettai to convene an online creditors' meeting on its restructuring scheme, granted a 16-week moratorium, and said there was no proper evidence supporting claims that Zettai had orchestrated the theft.
As of 2024-12-05, the company said it held liquid assets of 566.38 million USDT against total claims of 546.47 million USDT, providing an updated snapshot of its post-hack financial position.
Earlier in December 2024, WazirX reported freezing an initial tranche of stolen assets worth $3 million as part of efforts to recover funds taken in the July hack.
By early September 2024, CoinSwitch said its funds were trapped on WazirX and that it would pursue legal action, adding to mounting legal pressure on the exchange after the breach.
Following the July 18 wallet exploit, WazirX and custody provider Liminal blamed each other for security failures tied to the compromised multi-signature wallet. The dispute unfolded as customers criticized WazirX over transparency and frozen withdrawals.
On 2024-08-27, WazirX operating entity Zettai filed for a moratorium in the High Court of Singapore to support a Scheme of Arrangement aimed at restructuring liabilities and managing recovery after the hack.
In the aftermath of the hack, WazirX notified Indian police, launched bounty programs to trace stolen assets, and introduced a 'socialised loss strategy' under which users would initially receive 55% of their tokens while the remainder would be locked or otherwise managed for recovery.
By 2024-07-29, WazirX said the July 18 cyberattack had affected about 45% of its crypto assets and resulted in the theft of more than $230 million from one wallet. The exchange said it had held roughly $500 million in digital assets before the incident.
On 2024-07-18, WazirX disclosed a security breach affecting one of its multi-signature wallets and temporarily paused both Indian Rupee and cryptocurrency withdrawals while it investigated the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
economictimes.indiatimes.com
Open sourcethehindu.com
Open sourcethehindu.com
Open sourceindianexpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.