TL;DR
- Zilliqa found a Ledger app flaw that exposes private keys after roughly five native transactions.
- Native ZIL transactions were suspended, while EVM transactions remain unaffected.
- Upbit designated ZIL as a cautionary asset and warned trading support could be terminated.
- A patched Ledger app is ready, but compromised wallets will require new keys under a coordinated recovery plan.
Zilliqa has suspended native transactions after uncovering a critical vulnerability in its Ledger application that could allow attackers to reconstruct users’ private keys from publicly available blockchain signatures. The security issue, which existed in every released version of the Zilliqa Ledger app between 2019 and 2026, prompted South Korean crypto exchange Upbit to designate ZIL as a cautionary asset, raising the possibility of further trading restrictions if the issue is not fully resolved.
The blockchain team said the flaw affects only native (non-EVM) Zilliqa transactions signed with Ledger hardware wallets. According to the disclosure, any wallet that signed approximately five or more native transactions using the affected Ledger app should be considered compromised because its private key can be mathematically reconstructed from signatures already recorded on-chain.
To limit further losses, Zilliqa has halted all native transactions while it finalizes a coordinated recovery plan. The project stressed that users who may be affected should avoid taking independent action and instead wait for official instructions, warning that simply transferring funds would not adequately protect compromised wallets because attackers could potentially front-run any transaction once the network resumes.
Signature Flaw Traced to Weakened Nonce Generation
The vulnerability stems from an error in the app’s implementation of Schnorr signatures, which authenticate native Zilliqa transactions.
Each Schnorr signature relies on a unique, randomly generated ephemeral nonce. While the app initially generated enough randomness, a coding mistake copied the wrong 32-byte segment into the signing buffer. As a result, the most significant 64 bits of every nonce were fixed to zero, dramatically reducing the randomness required to keep private keys secure.
Security researchers explained that once around five affected signatures become publicly available, attackers can recover the corresponding private key within seconds using commodity hardware through a well-known cryptographic attack called the Hidden Number Problem solved via lattice reduction techniques. Because those signatures are permanently stored on-chain, updating the Ledger application cannot eliminate the exposure for wallets that have already signed vulnerable transactions. Those keys must ultimately be retired.
Zilliqa emphasized that the issue is isolated to the Ledger application’s native signing path. Users interacting exclusively through the network’s EVM-compatible environment or using official software development kits such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.
Ziliqa Exploitation Detected Before Public Disclosure
According to Zilliqa’s incident timeline, the defect had existed unnoticed across every Ledger app release since 2019.
The team said suspicious on-chain activity consistent with active exploitation was first observed on July 19. Engineers isolated the root cause two days later after reproducing the attack using publicly available blockchain signatures.
A corrected version of the Ledger application has already been prepared in coordination with Ledger and restores proper nonce generation. However, the update cannot secure wallets whose private keys have already been exposed, making a broader remediation process necessary before native transactions can safely resume.
Zilliqa also credited KuCoin’s security team for helping identify the vulnerability, successfully recovering affected private keys from public signatures during the investigation, and confirming that the exploit was actively being abused.
Following the disclosure, Upbit classified ZIL as a cautionary asset across its KRW and BTC markets, citing unresolved security concerns. The exchange has already suspended deposits and withdrawals and warned that trading support could ultimately be terminated if the project fails to sufficiently address the incident.
According to Upbit’s notice, the review period is expected to continue until the third week of August, after which the exchange will decide whether to remove the cautionary designation, extend the review, or delist the token altogether depending on the progress of Zilliqa’s remediation efforts.



