Zilliqa Halts Native Transactions Over Ledger App Key-Recovery Flaw
Zilliqa, a Layer-1 blockchain, uses EC-Schnorr signatures over secp256k1 for native ZIL transactions. A flaw present in every version of its Ledger app since 2019 copied the wrong 32 bytes from a 40-byte random value, fixing the nonce’s top 64 bits at zero. That weakened signatures enough for attackers to reconstruct a private key from about five publicly visible on-chain signatures, meaning previously exposed keys cannot be made safe by a software patch alone.
Zilliqa said on July 22, 2026, that it had suspended native transactions and asked exchanges to pause ZIL deposits and withdrawals after spotting activity consistent with active exploitation on July 19 and confirming the cause on July 21. It is working with Ledger on a corrected app and a coordinated recovery plan; KuCoin helped identify the flaw and reproduce private-key recovery. EVM transactions and Zilliqa SDKs, including zilliqa-js, are unaffected. The amount of ZIL stolen has not been disclosed.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.