Zilliqa has halted all native ZIL transactions after confirming that a critical flaw in its Ledger hardware wallet application allowed some private keys to be reconstructed from public blockchain data, exposing affected accounts to theft. The network suspension was confirmed on July 22 after Zilliqa detected active exploitation tied to a software defect that had been present since 2019.
The issue affects native ZIL transfers signed through the Ledger application. Zilliqa said transactions made through EVM-compatible environments and those using the Zilliqa SDK are not affected. Users who rely on Ledger devices for native ZIL transactions have been told to wait for further instructions while engineers complete and test a corrected version of the app.
The disclosure adds pressure to a project already facing market stress. ZIL fell 4.8% over 24 hours to $0.0024 at the time of the announcement, after touching a record low of $0.00235 on Wednesday morning. The token was down about 17% over seven days, reducing its market value to roughly $49 million.
The security incident has also landed during a separate regulatory review in South Korea, where Upbit placed ZIL on a strict delisting watch on July 20 under the country’s Virtual Asset User Protection Act. That review is expected to run until the week of August 17. Deposits and withdrawals for the token were suspended on the platform as part of the process.
Security flaw forces native transaction halt
Zilliqa said the pause was a protective measure after engineers confirmed that certain private keys could be recovered from signatures already recorded onchain. Because blockchain data is public and permanent, any weak signatures created in the past remain visible even after software is updated.
The company’s disclosure said the defect came from the way Schnorr signatures were generated for native ZIL transactions in the Ledger app. In simple terms, a digital signature requires fresh randomness each time a transaction is signed. That random value, known as a nonce, must never be predictable or reused. If it is weak, repeated, or partly predictable, attackers may be able to work backward from public signatures and recover the private key.
In this case, the flaw caused predictable nonces during the signing process. Zilliqa said the software copied the wrong 32 bytes from a 40-byte value, which effectively forced the upper 64 bits of each nonce to zero. That loss of randomness was enough to weaken the signatures to a dangerous level.
Once enough affected signatures were available, the private key protecting the account could be reconstructed. Zilliqa said roughly five transaction signatures could be enough for recovery in some cases. That means accounts that sent several native ZIL transfers with the vulnerable Ledger app may be at serious risk.
Why public blockchain data made the risk urgent
The most damaging part of the incident is that the information needed to exploit the bug is not hidden. Broken signatures remain on the blockchain permanently. Anyone inspecting the public record can see them. If enough vulnerable signatures are available for the same account, the private key may be recoverable without needing access to the user’s device.
That makes the problem different from a routine software bug that can be fixed simply by issuing an update. A patch can prevent new weak signatures from being created, but it cannot erase old signatures already published to the network. For accounts that have already produced enough vulnerable signatures, the past exposure may be irreversible.
This is why Zilliqa’s halt of native transactions is significant. The pause is intended to prevent further movement through the affected native transaction path while developers and security teams work on the response. It also gives the project time to prepare instructions for users who may need to move funds safely once a verified remediation process is available.
Zilliqa said affected activity was first identified onchain on July 19. The technical cause was isolated two days later. After that, engineering teams deployed mitigation steps and began working with Ledger on a corrected version of the application.
Who is affected and who is not
The most exposed group appears to be users who signed multiple native ZIL transactions with the Ledger app affected by the defect. Accounts that made five or more such transfers may face the highest risk because repeated weak signatures provide more data for private key reconstruction.
Zilliqa has advised users who rely on Ledger devices for native ZIL transfers to wait for official guidance. The company has said EVM-compatible transactions and activity through the Zilliqa SDK are not affected by the flaw.
The distinction is important. The issue is associated with the native signing flow in the Ledger app, not with every Zilliqa-related transaction method. It also does not automatically mean that all Ledger devices or all assets held on Ledger hardware wallets are compromised. The disclosed weakness concerns a specific application and signing process for native ZIL transactions.
Still, for affected accounts, the risk can be severe. If a private key has been reconstructed, control of the account may no longer belong only to the original owner. Any attacker with that key could attempt to move funds when transaction channels are available. For that reason, users are being urged to avoid initiating new native transfers until the project confirms a verified solution.
Assistance and technical response
Zilliqa said assistance from digital asset exchange KuCoin helped identify the nonce-handling problem, reconstruct compromised keys from disclosed data, and verify evidence that the flaw had been exploited. The company said the coordination helped immediate protection measures move ahead while longer-term software fixes were developed.
The corrected Ledger integration is expected to be released after validation and security testing are complete. No final release time has been announced. Until then, users are being guided toward caution rather than manual attempts to solve the issue on their own.
The project’s response now has two separate goals. The first is to stop new weak signatures from being created. That requires a corrected signing process in the Ledger app. The second is to help users whose accounts may already be exposed. That is more complicated because old signatures cannot be removed from the blockchain.
For accounts that have already generated enough vulnerable signatures, the safest long-term outcome would likely involve abandoning compromised addresses and using newly generated accounts that were not exposed through the flawed signing path. However, the timing and method of any migration must depend on official instructions, because native ZIL transfers have been paused and uncoordinated movement could create new risks.
Market reaction deepens pressure on ZIL
The security disclosure triggered another wave of selling in ZIL, which was already under strain from regulatory uncertainty in South Korea. The token traded at $0.0024 at the time of the announcement, down 4.8% over the previous 24 hours. Earlier, it had fallen to $0.00235, described as a record low, after losing about 17% over the week.
The decline pushed the project’s market value to about $49 million. For traders, the combination of a live security issue, a transaction halt, and a delisting review has created a difficult environment. Price swings are likely to remain sharp while uncertainty remains over the technical fix, account-migration process, and exchange support.
Liquidity conditions can also worsen when deposits and withdrawals are suspended. If traders cannot freely move tokens between platforms or wallets, price gaps can appear more easily. Market confidence often depends not only on whether a bug can be fixed, but also on how clearly a project communicates the path to recovery.
In Zilliqa’s case, the market is watching for three things: confirmation that the Ledger app update has passed security testing, instructions for accounts that may have exposed keys, and clarity from trading platforms reviewing the token.
Upbit review adds regulatory uncertainty
The South Korean exchange Upbit placed ZIL on a strict delisting watch on July 20, citing compliance with the Virtual Asset User Protection Act. The review period is expected to continue until the week of August 17. During that time, the token remains under heightened scrutiny.
Upbit also suspended deposits and withdrawals for ZIL on its platform. Such measures are often used during risk reviews, especially when a token is facing technical, operational, or user-protection concerns.
The regulatory review increases pressure on Zilliqa because South Korea remains one of the more active cryptocurrency trading markets. A delisting warning can affect trader sentiment even before a final decision is made. If a platform ultimately removes a token, access can narrow and liquidity can fall. If the token passes review, some pressure may ease, but that outcome is not guaranteed.
The separate timing of the Upbit review and the Ledger app security issue has made the overall situation more difficult. Even if the technical flaw is addressed quickly, the project must still navigate the exchange review process through mid-August.
Leadership faces early test
The incident also comes shortly after Oh Kyoung-suk assumed the role of company president on July 1. That means the leadership team is dealing with a major security event in Oh’s first month in the position.
Chief Executive Officer Alexander Zahnd’s public communications are expected to be closely followed by users and traders until the transaction pause is lifted and the Ledger integration is updated. Clear instructions will be especially important for users who may need to determine whether their accounts signed enough native transactions to be considered exposed.
The project now needs to balance speed with safety. Moving too slowly could leave users anxious and markets unsettled. Moving too quickly without full validation could create additional failures. For security teams, the priority is to ensure that the updated Ledger app eliminates the nonce problem and that any migration guidance does not expose users to new attack paths.
What happens next
The next major step is the release of the corrected Ledger app after validation and security testing. Zilliqa has not provided a final release date, saying the update will be made available once checks are complete.
Until then, the native transaction halt remains the clearest sign of the seriousness of the flaw. Users are being told not to initiate new native transfers through the affected path and to wait for verified instructions. Accounts that have used Ledger for multiple native ZIL transactions should be treated with caution, especially if they produced five or more signatures.
The long-term impact will depend on how many accounts were exposed, how much value remains in those accounts, how quickly a safe migration process can be completed, and whether exchanges maintain support after their reviews. The public nature of the blockchain means the technical evidence cannot be erased, so the recovery process must assume that past weak signatures remain permanently available.
For now, Zilliqa’s immediate task is containment. The project must prevent additional vulnerable signatures, protect remaining funds where possible, and restore trust through transparent updates. Traders, meanwhile, are likely to remain cautious until native transfers resume, the corrected Ledger app is released, and the Upbit review reaches a conclusion.
Worried about wallet risks? Strengthen your security with Toobit’s crypto safety guide and avoid similar vulnerabilities.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

