Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers

by Trevor Jones
0 comments



Zilliqa has suspended native ZIL transactions after disclosing a critical flaw in its Ledger application that can allow attackers to recover private keys from public transaction signatures. 

Summary

  • Zilliqa halted native transactions after a Ledger app flaw exposed private keys from public signatures.
  • Accounts signing roughly five native transactions with Ledger devices should be treated as compromised permanently.
  • Upbit flagged ZIL as cautionary while EVM transactions and Zilliqa software development kits remain unaffected.

The bug affected every released version of the app from 2019 through 2026 and applies to native, non-EVM transactions signed with Ledger devices.

The network said it observed onchain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. Zilliqa has prepared a corrected Ledger app build, but the fix cannot protect keys exposed through earlier signatures. Native transactions remained suspended in the latest official update while the team finalized a coordinated recovery plan.

Zilliqa Ledger bug weakened transaction signatures

The flaw affected how the Zilliqa Ledger app generated Schnorr signatures for native transactions. Each signature needs a fresh random number, known as a nonce, to protect the private key. Zilliqa said the app generated enough random data but copied the wrong 32 bytes into the signing process. The mistake left the highest 64 bits of every nonce fixed at zero.

The reduced randomness allowed attackers to compare several public signatures from the same account and reconstruct its private key. Zilliqa said accounts that broadcast roughly five or more affected native transactions should be treated as compromised. The project said the recovery process can take seconds on ordinary hardware once enough signatures are available.

Because the signatures remain permanently recorded onchain, updating the Ledger app cannot repair an already exposed key. Zilliqa said affected keys must be retired. It also warned against simply moving funds when transactions restart because an attacker holding the recovered key could try to send a competing transaction.

Native transactions stop while EVM users remain unaffected

Zilliqa suspended native transactions after identifying the flaw, blocking further native transfers while the team develops a method to protect affected balances. The project asked Ledger users who signed native transactions to wait for official instructions.

“Users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action,” Zilliqa noted.

The issue does not affect EVM transactions, according to Zilliqa. The project also said its software development kits, including zilliqa-js, gozilliqa-sdk and pyzil, generate nonces correctly. Users who only transact through EVM-compatible tools therefore sit outside the affected signing path.

Zilliqa credited KuCoin with helping trace the problem. The exchange recovered affected private keys from public signatures, helped confirm active exploitation and assisted in identifying the faulty nonce-generation process. Zilliqa said the cooperation helped it introduce protective measures while preparing a broader recovery plan.

Upbit places ZIL under caution after disclosure

South Korean exchange Upbit placed ZIL under cautionary status after the vulnerability became public. The designation covers its KRW and BTC markets, while ZIL deposits and withdrawals remain suspended. Trading support could face further review if the issue is not resolved through the exchange’s monitoring process.

The exchange action comes while Zilliqa works on securing balances controlled by keys that may already be recoverable. A corrected Ledger build has been prepared, but the project has not yet published its full recovery procedure or announced when native transactions will resume.

As crypto.news reported on July 20, Zilliqa had already asked exchanges to pause ZIL deposits and withdrawals after an exchange partner reported a cold-wallet theft. At that stage, the project had not disclosed the stolen amount, affected exchange or attack method. Zilliqa has not publicly stated whether that earlier theft was caused by the Ledger flaw.

Bug follows earlier Zilliqa network disruptions

The Ledger vulnerability differs from earlier Zilliqa outages because it affects private-key security rather than block production or node synchronization. Still, the disclosure follows several technical disruptions that affected the network in previous years.

Moreover, Zilliqa announced a permanent fix in September 2024 after a bug halted block production. The network later suffered another outage in January 2025 linked to node synchronization problems before restoring full service. Zilliqa has not connected those incidents to the Ledger app flaw.

The current issue also sits outside Ledger hardware itself. Zilliqa described the problem as a defect in its own Ledger application’s native signing code. The corrected build restores full-width nonce generation and should prevent new weak signatures once released.

For affected users, the old transaction history remains the main risk. Public signatures cannot be removed from the blockchain. Zilliqa said users who signed about five or more native transactions with a Ledger device should consider their keys compromised and wait for recovery instructions. The network has not announced a date for restoring native transactions.



Source link

You may also like

Latest News

© 2025 blockchainecho.xyz. All rights reserved.