- Zilliqa halted its local sale after realizing a major risk in using its Ledger wallet.
- The flaw could allow attackers to recreate private keys from commercial signatures that have been created several years ago.
- The exchange has suspended ZIL transfers while the network prepares recovery instructions for affected users.
- This issue is limited to the Zilliqa Ledger software and does not affect the Ledger hardware or the EVM network.
Zilliqa has suspended all birth (non-EVM) transactions after confirming a major security vulnerability in its Ledger hardware wallet software, a flaw that could allow attackers to recover users’ private keys from publicly available blockchain signatures. The emergency method comes when the project is working with security researchers and exchanges to contain the incidents and create a recovery plan for the users who may be affected.
According to X’s announcementthe vulnerability is limited to the Zilliqa blockchain and does not affect its associated EVM network.
Ledger hardware also remains untouched, it’s just a matter of installing the Zilliqa Ledger application.
Research traced the error to a decades-old error
According to Zilliqa, the vulnerability stemmed from a flaw in the use of Schnorr signatures, a secret mechanism used to authenticate local transactions.
As our investigation progresses, we would like to clarify one important point:
So far, we have not found any evidence that this incident was caused by the wallet management or wallet usage. We appreciate the cooperation of this change in recognition of… https://t.co/i6UQ62m4CM
— Zilli (@zilliqa) July 20, 2026
Instead of generating ambiguous nonces for each signature, the buffer-copy error caused the most significant 64 bits of each nonce to be overwritten with zeros. This greatly reduced the volatility that protects each signature, and created conditions where attackers could regenerate private keys using string reduction techniques after seeing enough events on the chain.
The service said the vulnerable code has been present in every version of the Zilliqa Ledger software since its release in 2019, meaning the flaw went undetected for nearly six years.
Investigations intensified after suspicious activity on the chain was discovered on July 19. Working with exchange partners, including KuCoin, researchers traced the attack to the Ledger application signing process before publicly confirming the vulnerability on July 21. A day later, Zilliqa suspended all public transactions while mitigation efforts began.
Only a special group of users is at risk
Vulnerability does not affect everyone with ZIL in the same way. Based on project guidance, the high-risk group includes users who:
- I used a Ledger device for doing native (non-EVM) ZIL transactions.
- Signed between 2019 and July 2026.
- It has generated at least five or more signatures with the same private key.
The project emphasized that several aspects of its environment are not affected:
- Ledger hardware is not tampered with.
- Zilliqa’s EVM-compatible blockchain continues to perform well.
- Software wallets are not vulnerable to vulnerabilities.
Zilliqa urged affected users not to transfer funds or attempt to become independent until migration guidelines are issued, warning that immediate action could make the recovery process difficult.
Exchanges move quickly so you have a potential problem
The revelation led to an immediate reaction on cryptocurrency trading platforms.
A river in South Korea placed ZIL as a warning objectDeposits are suspended and withdrawn, marking the withdrawal in mid-August under the Investor Protection Policy.
Another central exchange temporarily suspended the transfer of ZIL while investigating the Ledger software crash and reports of other thefts involving ZIL stored in a cold wallet controlled by one of the ecosystem’s partners. Although the events are different, their close timing has raised concerns in the market.
Investor sentiment fell after the disclosure. ZIL is down about 5% in the past 24 hours and about 17% over the past week, falling to around $0.0024 as traders assess the security’s growth.
Recovery Now Dependent on Changing Transparent Wallets
Unlike most software problems, this event goes beyond the deployment of a standard program. Because the signatures of transactions at risk are already recorded on the blockchain, updating the Ledger software will not eliminate the transparency associated with signatures created in the last six years.
The next phase of the response will therefore focus on the migration of affected users to the newly created wallets rather than restoring the damaged ones. This is expected to require communication between Zilliqa, Ledger, Digito currency exchange and wallet holders before native internet services can be implemented.






