ARTFEED — Contemporary Art Intelligence

Zilliqa Halts Native Transactions After Ledger App Flaw Exposes Private Keys

other · 2026-07-24

Due to a serious vulnerability in its Ledger application, Zilliqa has suspended all native ZIL transactions. This security flaw, which has existed in app versions since 2019, allows the recovery of private keys from public signatures. An undisclosed quantity of ZIL was stolen from a partner exchange's cold wallet, prompting Zilliqa to ask centralized platforms to halt ZIL deposits and withdrawals. The vulnerability was exploited on July 19, 2026, and made public the following day. It particularly affects accounts with five or more native transactions through the Ledger app. While a fix is in development, it will not mitigate prior exposure. Zilliqa has not disclosed the amount stolen or the accounts impacted.

Key facts

  • Zilliqa halted native ZIL transactions due to a Ledger app vulnerability that exposes private keys.
  • The flaw allows private key recovery from public signatures on the blockchain.
  • An undisclosed amount of ZIL was stolen from an exchange partner's cold wallet.
  • The vulnerability existed in app versions since 2019, with exploitation detected on July 19, 2026.
  • Accounts that signed approximately 5 or more native transactions via the Zilliqa Ledger app are considered compromised.
  • The root cause is a nonce generation flaw: 8 bytes of entropy are discarded, leaving 64 bits of nonce fixed at zero.
  • Private keys can be recovered in seconds using Hidden Number Problem and lattice reduction techniques.
  • KuCoin assisted in identifying the root cause and confirming ongoing exploitation.

Entities

Institutions

  • Zilliqa
  • Ledger
  • KuCoin
  • NFT Plazas

Sources