Close Menu

    Subscribe to Updates

    What's Hot

    Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers

    July 23, 2026

    The 1.x Files: The State of Stateless Ethereum

    July 23, 2026

    AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH

    July 23, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers
    Crypto

    Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers

    John SmithBy John SmithJuly 23, 2026No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Zilliqa has suspended native ZIL transactions after disclosing a critical flaw in its Ledger application that can allow attackers to recover private keys from public transaction signatures. 

    Summary

    • Zilliqa halted native transactions after a Ledger app flaw exposed private keys from public signatures.
    • Accounts signing roughly five native transactions with Ledger devices should be treated as compromised permanently.
    • Upbit flagged ZIL as cautionary while EVM transactions and Zilliqa software development kits remain unaffected.

    The bug affected every released version of the app from 2019 through 2026 and applies to native, non-EVM transactions signed with Ledger devices.

    The network said it observed onchain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. Zilliqa has prepared a corrected Ledger app build, but the fix cannot protect keys exposed through earlier signatures. Native transactions remained suspended in the latest official update while the team finalized a coordinated recovery plan.

    Zilliqa Ledger bug weakened transaction signatures

    The flaw affected how the Zilliqa Ledger app generated Schnorr signatures for native transactions. Each signature needs a fresh random number, known as a nonce, to protect the private key. Zilliqa said the app generated enough random data but copied the wrong 32 bytes into the signing process. The mistake left the highest 64 bits of every nonce fixed at zero.

    The reduced randomness allowed attackers to compare several public signatures from the same account and reconstruct its private key. Zilliqa said accounts that broadcast roughly five or more affected native transactions should be treated as compromised. The project said the recovery process can take seconds on ordinary hardware once enough signatures are available.

    Because the signatures remain permanently recorded onchain, updating the Ledger app cannot repair an already exposed key. Zilliqa said affected keys must be retired. It also warned against simply moving funds when transactions restart because an attacker holding the recovered key could try to send a competing transaction.

    Native transactions stop while EVM users remain unaffected

    Zilliqa suspended native transactions after identifying the flaw, blocking further native transfers while the team develops a method to protect affected balances. The project asked Ledger users who signed native transactions to wait for official instructions.

    “Users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action,” Zilliqa noted.

    The issue does not affect EVM transactions, according to Zilliqa. The project also said its software development kits, including zilliqa-js, gozilliqa-sdk and pyzil, generate nonces correctly. Users who only transact through EVM-compatible tools therefore sit outside the affected signing path.

    Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated… https://t.co/sudV7WA3TV

    — Zilliqa (@zilliqa) July 22, 2026

    Zilliqa credited KuCoin with helping trace the problem. The exchange recovered affected private keys from public signatures, helped confirm active exploitation and assisted in identifying the faulty nonce-generation process. Zilliqa said the cooperation helped it introduce protective measures while preparing a broader recovery plan.

    Upbit places ZIL under caution after disclosure

    South Korean exchange Upbit placed ZIL under cautionary status after the vulnerability became public. The designation covers its KRW and BTC markets, while ZIL deposits and withdrawals remain suspended. Trading support could face further review if the issue is not resolved through the exchange’s monitoring process.

    The exchange action comes while Zilliqa works on securing balances controlled by keys that may already be recoverable. A corrected Ledger build has been prepared, but the project has not yet published its full recovery procedure or announced when native transactions will resume.

    As crypto.news reported on July 20, Zilliqa had already asked exchanges to pause ZIL deposits and withdrawals after an exchange partner reported a cold-wallet theft. At that stage, the project had not disclosed the stolen amount, affected exchange or attack method. Zilliqa has not publicly stated whether that earlier theft was caused by the Ledger flaw.

    Bug follows earlier Zilliqa network disruptions

    The Ledger vulnerability differs from earlier Zilliqa outages because it affects private-key security rather than block production or node synchronization. Still, the disclosure follows several technical disruptions that affected the network in previous years.

    Moreover, Zilliqa announced a permanent fix in September 2024 after a bug halted block production. The network later suffered another outage in January 2025 linked to node synchronization problems before restoring full service. Zilliqa has not connected those incidents to the Ledger app flaw.

    The current issue also sits outside Ledger hardware itself. Zilliqa described the problem as a defect in its own Ledger application’s native signing code. The corrected build restores full-width nonce generation and should prevent new weak signatures once released.

    For affected users, the old transaction history remains the main risk. Public signatures cannot be removed from the blockchain. Zilliqa said users who signed about five or more native transactions with a Ledger device should consider their keys compromised and wait for recovery instructions. The network has not announced a date for restoring native transactions.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH

    July 23, 2026

    UK Treasury races to solve cash barrier before tokenized bond debut

    July 23, 2026

    S&P and Pantera exclude Bitcoin from new revenue-based crypto index

    July 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers

    By John SmithJuly 23, 20260

    Zilliqa has suspended native ZIL transactions after disclosing a critical flaw in its Ledger application…

    The 1.x Files: The State of Stateless Ethereum

    July 23, 2026

    AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH

    July 23, 2026

    Update on the Vyper Compiler

    July 23, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (10)
    • Bitcoin (3)
    • Blockchain (16)
    • Crypto (721)
    • Ethereum (358)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.