NewsCryptoZilliqa Faces Security Crisis as Upbit and Bithumb Add ZIL to Warning Lists

Zilliqa Faces Security Crisis as Upbit and Bithumb Add ZIL to Warning Lists

Author: Bitcoinsistemi·

Key Takeaways

  • A critical vulnerability in Zilliqa's Ledger hardware wallet application makes private keys for ZIL transactions susceptible to recovery attacks by malicious actors.
  • The security flaw impacts every version of the Ledger ZIL app released between 2019 and 2026, with active exploitation first observed on July 19.
  • Zilliqa suspended native ZIL transactions as a precaution, while Ethereum Virtual Machine transactions on the network remain unaffected.
  • Upbit and Bithumb designated ZIL as a warning asset, suspended deposits and withdrawals, and warned that trading support may be terminated if the issue persists.
  • Users who have used Ledger hardware wallets for ZIL transactions are strongly advised to migrate their funds to new addresses and stop using potentially compromised wallets.
Zilliqa Faces Security Crisis as Upbit and Bithumb Add ZIL to Warning Lists

Zilliqa (ZIL), a blockchain platform that gained prominence during the 2021 bull market as one of the early projects to implement sharding for scalability, has disclosed a significant security crisis stemming from a critical vulnerability in its Ledger hardware wallet application.

In a statement published on its official X (formerly Twitter) account, Zilliqa confirmed that the vulnerability resides within the Ledger app designed for ZIL transactions. Ledger hardware wallets are widely used across the cryptocurrency industry precisely because they are designed to keep private keys offline and beyond the reach of remote attackers — a security premise that this vulnerability directly undermines. The flaw makes private keys used for ZIL transfers susceptible to recovery attacks, potentially allowing malicious actors to reconstruct and compromise users' keys.

Scope of the Vulnerability

The Zilliqa team reported that the issue affects all versions of the Ledger application released between 2019 and 2026. Active exploitation of the vulnerability was first observed on July 19, prompting an immediate response from the development team. As a precautionary measure, ZIL native transactions were suspended. However, the team emphasized that Ethereum Virtual Machine (EVM) transactions on the Zilliqa network remain unaffected by this security flaw.

Korean Exchanges Respond

In the wake of the disclosure, two of South Korea's largest cryptocurrency exchanges — Upbit and Bithumb — classified ZIL as a "warning asset" in their respective trading markets. South Korean exchanges operate under regulatory frameworks that require them to flag digital assets posing potential risks to investors, and a warning designation is typically an intermediate step before possible delisting. Both exchanges cited user security concerns as the basis for their decisions and announced the suspension of ZIL deposits and withdrawals.

Upbit and Bithumb issued similarly worded statements cautioning that if the security issue is not resolved within a reasonable timeframe, or if adequate investor protection measures are not implemented, trading support for ZIL could be terminated entirely.

User Advisory

The incident has triggered a broader review of security protocols within the Zilliqa ecosystem. Users who have conducted ZIL transactions through a Ledger hardware wallet are strongly advised to migrate their funds to new addresses and cease using any potentially compromised wallets.

Prior Security Incident

This is not the first security challenge Zilliqa has faced. The project previously reported that ZIL held in a cold wallet was stolen during a security breach at one of its partner exchanges.

The original source article is available at bitcoinsistemi.