Zilliqa suspends transactions after Ledger app flaw

Zilliqa halted native ZIL transactions after a Ledger app flaw exposed private keys. The issue is being fixed, and protective measures are in place.

Zilliqa has suspended all native ZIL transactions after discovering a critical vulnerability in its Ledger hardware wallet app, present since 2019. The flaw, tied to the generation of Schnorr signatures for native transactions, stemmed from improper handling of cryptographic nonce data—specifically, the most significant 64 bits of each ephemeral nonce were set to zero. This significantly reduced randomness, enabling attackers to reconstruct private keys from as few as five onchain signatures, thereby endangering user funds. Importantly, the vulnerability does not impact EVM transactions or the network’s SDKs. Zilliqa detected active exploitation on July 19, 2026, quickly isolated the issue, and implemented protective measures, including suspending native transactions. Upbit flagged ZIL as a cautionary asset, and KuCoin assisted in identifying the exploit. A remediation plan and an updated Ledger app are being developed in coordination with Ledger. Further guidance for affected users will be provided soon.

Related Tokens

Related News