Zilliqa Faces Fallout From Critical Ledger Wallet Flaw

Blockonomics
Bybit



All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders.
  • Zilliqa suspended native transactions after identifying a critical vulnerability in its Ledger wallet application.
  • The flaw could allow attackers to reconstruct private keys from transaction signatures generated over several years.
  • Exchanges have restricted ZIL transfers while the network prepares recovery instructions for affected users.
  • The issue is limited to Zilliqa’s native Ledger application and does not affect Ledger hardware or the EVM network.

Zilliqa has suspended all native (non-EVM) transactions after confirming a critical security vulnerability in its Ledger hardware wallet application, a flaw that could allow attackers to recover users’ private keys from publicly available blockchain signatures. The emergency measure comes as the project works with security researchers and exchanges to contain the incident and develop a recovery process for potentially affected users.

According to the announcement in X, the vulnerability is limited to Zilliqa’s native blockchain and does not impact its EVM-compatible network.

Ledger hardware devices themselves also remain unaffected, with the issue confined to the software implementation of the Zilliqa Ledger application.

Investigation traced the flaw to a years-old cryptographic bug

According to Zilliqa, the vulnerability originated from an implementation error in its use of Schnorr signatures, the cryptographic scheme used to authorize native transactions.

Betfury

Rather than generating fully random nonces for each signature, a buffer-copy mistake caused the highest 64 bits of every nonce to be overwritten with zeros. That significantly reduced the randomness protecting each signature, creating conditions under which attackers could reconstruct private keys using lattice reduction techniques after observing enough transactions on-chain.

The project said the vulnerable code had existed in every version of the Zilliqa Ledger application since its initial release in 2019, meaning the flaw remained undiscovered for nearly six years.

The investigation accelerated after suspicious on-chain activity was detected on July 19. Working alongside exchange partners, including KuCoin, engineers traced the attacks to the Ledger application’s signing process before publicly confirming the vulnerability on July 21. One day later, Zilliqa suspended all native transactions while mitigation efforts began.

Only a specific group of users is considered at risk

The vulnerability does not affect every ZIL holder equally. Based on the project’s guidance, the highest-risk group includes users who:

  • Used a Ledger device for native (non-EVM) ZIL transactions.
  • Signed transactions between 2019 and July 2026.
  • Generated approximately five or more signatures with the same private key.

The project emphasized that several parts of its ecosystem remain unaffected:

  • Ledger hardware devices were not compromised.
  • Zilliqa’s EVM-compatible blockchain continues operating normally.
  • Software wallets are not impacted by the vulnerability.

Zilliqa has urged potentially affected users not to move funds or attempt independent recovery until official migration instructions are published, warning that premature action could complicate the recovery process.

Exchanges move quickly to contain potential fallout

The disclosure prompted immediate action across cryptocurrency trading platforms.

South Korea’s Upbit classified ZIL as a cautionary asset, suspended deposits and withdrawals, and placed the token under a delisting review through mid-August under the country’s investor protection framework.

Other centralized exchanges also temporarily restricted native ZIL transfers while evaluating the potential impact of both the Ledger application vulnerability and reports of a separate theft involving ZIL held in an offline cold wallet managed by one of the ecosystem’s exchange partners. Although the incidents are distinct, their close timing intensified concerns across the market.

Investor sentiment deteriorated following the disclosure. ZIL declined roughly 5% over the previous 24 hours and about 17% over the past week, falling to around $0.0024 as traders assessed the scale of the security incident.

Recovery Now Depends on Replacing Exposed Wallets

Unlike many software vulnerabilities, this incident extends beyond deploying a patched application. Because the vulnerable transaction signatures have already been permanently recorded on the blockchain, updating the Ledger app cannot eliminate the exposure associated with signatures created over the past six years.

The next phase of the response will therefore focus on migrating affected users to newly generated wallets rather than restoring the compromised ones. That process is expected to require coordination between Zilliqa, Ledger, cryptocurrency exchanges and wallet holders before native network activity can fully normalize.





Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*