Zilliqa Suspends Native Transfers After Critical Ledger App Vulnerability Exposes Private Keys
Key Takeaways
- •A critical nonce-generation vulnerability in the Zilliqa Ledger app could allow attackers to recover users' private keys after approximately five native transactions signed through the device.
- •Zilliqa halted all native ZIL transfers and advised affected users to immediately rotate their keys, as compromised signature data cannot be removed from the blockchain.
- •Upbit placed ZIL under cautionary status and began a delisting review, contributing to an approximately 10% drop in the token's price.
- •EVM-compatible transactions and software wallets were unaffected by the flaw, which was limited to native non-EVM Zilliqa transfers.
- •Zilliqa is working with exchange partners such as KuCoin to trace stolen funds and is developing a patched version of its Ledger application.

Zilliqa has halted all native ZIL transfers after a critical vulnerability in its Ledger hardware wallet application left users' private keys exposed, triggering an exchange-level response and a sharp decline in the token's price. The incident highlights a often-overlooked risk in hardware wallet security: while devices like Ledger are designed to keep private keys isolated from internet-connected systems, the third-party blockchain applications that run on them can still introduce exploitable flaws.
Upbit Places ZIL Under Cautionary Status
Upbit, South Korea's largest cryptocurrency exchange, swiftly placed ZIL under cautionary status and initiated a delisting review. Trading has not yet been suspended, but the exchange's action reflects serious concern over the security implications and potential risks to investors. ZIL fell approximately 10% following the announcement.
Technical Details of the Vulnerability
The flaw resides in how the Zilliqa Ledger app handled randomness — specifically the nonce — in Schnorr signatures for native (non-EVM) Zilliqa transactions. After approximately five native transactions signed through the Ledger app, attackers could potentially derive the user's private key using standard computing power. Nonce-generation flaws are a well-documented class of cryptographic vulnerability: when signatures reuse or produce predictable nonces, the underlying private key can be mathematically recovered from the public signature data. In this case, the exposure is permanent because every signature is recorded on-chain.
Zilliqa warned that any account that used the affected Ledger app should be considered compromised, as the leaked signature data is permanently recorded on-chain.
The project disclosed the vulnerability via its official X account:
Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated… — Zilliqa (@zilliqa) July 22, 2026
Scope of the Issue
EVM-compatible transactions and software wallets appear unaffected by the vulnerability. Zilliqa, together with exchange partners including KuCoin, has been working to trace stolen funds. The bug was publicly disclosed around July 21.
Guidance for Affected Users
Users who conducted native Zilliqa transfers through the Ledger app are advised to rotate their keys immediately. Zilliqa has emphasized that affected accounts should be treated as fully compromised given that signature data exposed on-chain cannot be removed.
The incident underscores that hardware wallet security depends not only on the physical device but also on the integrity of the application layer running on it. Whether Upbit proceeds with delisting and whether Zilliqa ships a patched Ledger app are key developments to monitor. Zilliqa is currently coordinating with exchanges and partners to mitigate the fallout while working on a resolution.
Source: DailyCoin