Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Zilliqa Suspends Native Transactions After Discovering Critical 7-Year-Old Ledger App Vulnerability Exposing Private Keys
00

Zilliqa Suspends Native Transactions After Discovering Critical 7-Year-Old Ledger App Vulnerability Exposing Private Keys

Jul 22, 2026

On July 21, 2026, Zilliqa suspended native ZIL transactions after identifying a critical vulnerability in its Ledger app dating back to 2019. The flaw, caused by incorrect byte copying during Schnorr signature nonce generation, leaves the most significant 64 bits of affected nonces fixed at zero. According to Zilliqa, attackers can reconstruct private keys from approximately five or more affected onchain signatures using lattice reduction. Zilliqa credited KuCoin with helping identify the root cause, recover affected private keys from publicly available signatures, and confirm active exploitation. A corrected app is being prepared in coordination with Ledger, and affected users were advised to await official instructions.

Zilliqa Ledger app vulnerability

  • ▪Zilliqa suspended native ZIL transactions on July 21, 2026, after discovering a critical security vulnerability in its official Ledger hardware wallet application
  • ▪The vulnerability affects every version of the Zilliqa Ledger app released since its launch in 2019

Schnorr signature nonce generation flaw

  • ▪The signing routine copied the wrong 32 bytes from a 40-byte randomness value, leaving the most significant 64 bits of every affected nonce fixed at zero
  • ▪The vulnerability stems from a flaw in ephemeral nonce generation during EC-Schnorr signature creation for native, non-EVM Zilliqa transactions

Private key exposure risk

  • ▪The private key exposure risk cannot be reversed by updating the Ledger app because the weakened signatures are permanently recorded on-chain
  • ▪The reduction in nonce randomness allows attackers to reconstruct a user's private key from approximately five or more on-chain signatures using lattice reduction

Native transaction suspension

  • ▪Zilliqa suspended native, non-EVM transactions on July 21, 2026, to prevent further draining of affected accounts
  • ▪EVM-compatible transactions and official Zilliqa software development kits, including zilliqa-js, gozilliqa-sdk, and pyzil, remain completely unaffected

KuCoin investigation cooperation

  • ▪Zilliqa credited KuCoin with reporting the issue, recovering affected private keys from publicly available onchain signatures, and confirming active exploitation
  • ▪Zilliqa detected on-chain activity consistent with active exploitation of the vulnerability on July 19, 2026

Coordinated remediation plan

  • ▪Zilliqa advised affected users to take no independent action, avoid moving funds, and await official instructions regarding a coordinated remediation plan
  • ▪Zilliqa and Ledger are preparing a corrected version of the Ledger app that restores full-width nonce generation

8 sources

Cryptotimes
Zilliqa Reveals Five-Year Ledger Wallet Vulnerability Exposing Private Key
View source article
Kucoin
Zilliqa Ledger App Vulnerability Exposes Native Transaction Signatures | KuCoin
View source article
News
Zilliqa Halts Native Transactions After Seven-Year Ledger Bug Exposed Private Keys
View source article
Cryptobriefing
Zilliqa suspends native transactions after critical Ledger bug exposed private keys since 2019
View source article
Thecurrencyanalytics
Zilliqa Kills Native Transactions After 7-Year-Old Ledger Private Key Bug Surfaces | The Currency analytics
View source article

Story comments

Loading comments…

Related Projects

Zilliqa

Topics

Layer 1sCryptography & hashingPrivate key management