Particle.news
Download on the App Store

Zilliqa Suspends Native ZIL Transfers After Ledger App Flaw Exposes Keys

A coding error in the Ledger companion app weakened Schnorr signature nonces, requiring users who made several native signatures to retire those wallets before native transfers restart.

Overview

  • Zilliqa halted all native (non‑EVM) ZIL transactions after detecting suspicious on‑chain activity on July 19, 2026 and isolating the app’s nonce bug on July 21, 2026.
  • The flaw came from the Ledger companion app copying the wrong bytes into the nonce buffer so the top 64 bits of each Schnorr nonce were fixed, which cuts signature entropy enough that about five signatures let attackers reconstruct a private key.
  • The bug existed in every released Zilliqa Ledger app build from 2019 through 2026, so signatures already recorded onchain can make keys vulnerable retroactively and cannot be fixed by a software update alone.
  • A corrected Ledger app build has been prepared with Ledger’s cooperation but cannot protect keys already exposed, so affected users must generate new keys and await Zilliqa’s coordinated recovery and exchange remediation plan.
  • Exchanges have taken protective steps—Upbit flagged ZIL as cautionary and suspended deposits and withdrawals—and Zilliqa credited KuCoin’s security team with helping recover exposed keys and confirm active exploitation.