Zilliqa halts native transactions over bug in its Ledger app dating to 2019

EcosystemsJuly 22, 2026, 8:39AM EDT
Zilliqa halts native transactions over bug in its Ledger app dating to 2019
Partner offers

Quick Take

  • Zilliqa suspended native transactions after disclosing a bug in its Ledger app dating to 2019 that allows private keys to be recovered from affected onchain signatures.
  • The flaw affects native ZIL transactions signed with Ledger devices, while EVM transactions and Zilliqa SDKs remain unaffected.

We'd love your feedback.

Advertisement

Zilliqa has suspended native ZIL transactions after uncovering a critical vulnerability in its Ledger application that has existed since 2019, making private keys used for affected transactions recoverable from publicly available onchain signatures.

In a statement posted to X on Wednesday, the Zilliqa team said the vulnerability affects the generation of Schnorr signatures for native Zilliqa transactions. The bug causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key using publicly available onchain data.

According to the statement, the team observed onchain activity consistent with active exploitation on July 19 before isolating the root cause on July 21. It attributed the issue to incorrect handling of cryptographic nonce data, where the signing routine copied the wrong 32 bytes from a 40-byte value, leaving the most significant 64 bits of each nonce fixed at zero. 

That reduction in randomness allowed private keys to be reconstructed from approximately five or more affected signatures using publicly available onchain data, the team said. 

Per the statement, protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalized. A corrected version of the Zilliqa Ledger app is being prepared in coordination with Ledger, with release details to be announced separately. 

Meanwhile, users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action, the team said. It added that users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected by the vulnerability.

The team also credited KuCoin for helping identify the root cause of the app's nonce generation flaw, recovering affected private keys from publicly available onchain signatures, and confirming that the vulnerability was being actively exploited. 

Zilliqa said the exchange's reporting and cooperation enabled the implementation of protective measures while the remediation plan was being developed.

Zilliqa's ZIL (ZIL) token traded down 4.8% over the past 24 hours at $0.0024, according to The Block's Zilliqa price page.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.