On July 21, 2026, Zilliqa suspended native ZIL transactions after identifying a critical vulnerability in its Ledger app dating back to 2019. The flaw, caused by incorrect byte copying during Schnorr signature nonce generation, leaves the most significant 64 bits of affected nonces fixed at zero. According to Zilliqa, attackers can reconstruct private keys from approximately five or more affected onchain signatures using lattice reduction. Zilliqa credited KuCoin with helping identify the root cause, recover affected private keys from publicly available signatures, and confirm active exploitation. A corrected app is being prepared in coordination with Ledger, and affected users were advised to await official instructions.
Story comments
Loading comments…