#What Vulnerability Affects Zilliqa’s Ledger Hardware Wallet?
A significant security flaw has been discovered in Zilliqa’s Ledger hardware wallet app, which has remained undetected for seven years. This vulnerability, present since the application’s launch in 2019, exposes users to the risk of having their private keys retrieved through publicly available on-chain data.
Zilliqa confirmed that the exploitation began on July 19, 2026, leading them to take decisive action by suspending all native ZIL transactions just two days later. The issue lies in how the Ledger app generates nonces for EC-Schnorr signatures during ZIL transactions. Specifically, the most significant 64 bits of the nonce were improperly fixed to zero due to a mishandling of data. This predictable nonce allows attackers to use visible signatures to reverse-engineer users' private keys through a method known as lattice reduction.
This is not a problem with Zilliqa’s blockchain or Ledger’s core hardware security, but rather a flaw in the software that connects Ledger devices to the Zilliqa network. This means other SDKs and EVM-compatible transactions remain unaffected and secure.
#What Are the Immediate Consequences?
The repercussions of this flaw are significant. Upbit, one of South Korea's leading crypto exchanges, has identified ZIL as a risky asset and has halted both deposits and withdrawals. Other exchanges are also closely monitoring the situation, which puts additional pressure on trading volumes.
Zilliqa’s team has handled the crisis with a combination of urgent management and strategic communication. Following the identification of the root cause on July 21, they have been working directly with Ledger to develop a comprehensive solution. Importantly, they have advised users whose keys may have been compromised to avoid transferring them. Instead, affected users should generate new keys through secure methods and regard the old keys as permanently compromised.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#What Should Investors Do Now?
Currently, ZIL holders are left wondering how long the suspension of native transactions will last. The resolution of this issue requires effective coordination between Zilliqa and Ledger, and until a reliable solution is released, audited, and assured, native transactions will likely remain on hold.
For those with ZIL stored on a Ledger device, the most pressing priority is clear: do not attempt to move any funds with the compromised app. It is essential to await official instructions from Zilliqa regarding the key retirement and recovery process.
Investors must remain vigilant as the situation develops. Trading activity for ZIL could be affected significantly based on the resolutions implemented and the overall market's reaction to the vulnerability and its fallout.