Tech

Zilliqa Halts Native Transactions After Discovering Critical Ledger Wallet Bug Dating Back to 2019

Zilliqa has temporarily suspended all native ZIL transactions after discovering a critical vulnerability in its Ledger hardware wallet application that dates back to 2019. The flaw could allow attackers to reconstruct users’ private keys from publicly available blockchain signatures, potentially giving them access to affected wallets. While the issue impacts only native ZIL transactions signed through the legacy Ledger app, Zilliqa emphasized that its blockchain, Zilliqa 2.0, EVM-compatible transactions, and developer SDKs remain secure.

The network acted quickly by pausing native transactions and coordinating with Ledger to develop a patched application before additional users could be affected. The incident follows reports of an exchange cold wallet compromise linked to the vulnerability and serves as another reminder that wallet software can introduce security risks even when the underlying blockchain remains uncompromised.

Critical Ledger Bug Exposed Private Keys

According to Zilliqa, the vulnerability existed in every released version of its native Ledger application since 2019.

The flaw:

  • Affected native ZIL transactions signed with Ledger devices.
  • Generated predictable cryptographic signing nonces.
  • Allowed attackers to recover private keys using publicly available on-chain signatures.
  • Required approximately five or more affected signatures to reconstruct a private key.

Because blockchain signatures are permanently stored on-chain, any vulnerable signatures created over the past several years remain publicly accessible.

Native Transactions Temporarily Suspended

To prevent further exploitation, Zilliqa immediately halted native network transactions.

The emergency response included:

  • Suspending native ZIL transfers.
  • Coordinating with Ledger on a patched wallet application.
  • Working with exchanges to pause deposits and withdrawals where necessary.
  • Launching a coordinated remediation plan for affected users.

The network said normal operations will resume after the updated Ledger application has been fully deployed.

Zilliqa 2.0 and EVM Transactions Remain Safe

The project stressed that the vulnerability does not affect the underlying blockchain itself.

According to the team:

  • Zilliqa 2.0 remains secure.
  • EVM-compatible transactions are unaffected.
  • Zilliqa SDKs were not impacted.
  • Only the legacy native Ledger application contains the vulnerable signing implementation.

This distinction is important because the issue originated in wallet software rather than the blockchain’s consensus mechanism or smart contract infrastructure.

Users Urged to Wait for Official Guidance

Developers warned users not to move funds until remediation instructions are released.

Users who:

  • Signed native ZIL transactions using Ledger devices.
  • Generated multiple historical signatures.
  • Used the vulnerable Ledger application since 2019.

may need to migrate assets to newly generated wallets after official recovery procedures become available.

The team said additional guidance will be published once the patched Ledger application has completed testing.

Exchange Theft Triggered Investigation

The vulnerability came to light after Zilliqa identified suspicious activity involving a cold wallet belonging to one of its exchange partners.

While the project has not publicly identified the exchange or disclosed the amount stolen, investigators determined that the compromise was connected to the long-standing Ledger application bug, prompting the immediate suspension of native transactions.

Security teams continue monitoring affected wallets while coordinating with exchanges and infrastructure providers.

Hardware Wallet Software Can Still Create Risk

Although Ledger hardware wallets are widely regarded as one of the safest methods for storing cryptocy, the incident highlights that vulnerabilities can still arise through wallet applications.

Even when private keys never leave a hardware device, flawed cryptographic implementations can weaken transaction signatures and expose users to attacks if software is improperly designed.

Terron Gold

Recent Posts

U.S. Government Puts GDP and Inflation Data Onchain With Chainlink

Official U.S. economic data is moving directly onto public blockchains. The U.S. Department of Commerce…

12 hours ago

World Wants to End Oversharing Your ID With New Zero-Knowledge Privacy Tool

World is opening up the privacy technology behind World ID to everyone. The Sam Altman-backed…

18 hours ago

Wyoming Makes Its State Stablecoin More Transparent With Chainlink Proof of Reserve

Wyoming is adding another layer of blockchain infrastructure to its state-issued stablecoin. The Wyoming Stable…

2 days ago

Socios and Securitize Team Up to Bring Sports Team Ownership Onchain

Sports fan tokens may be about to get a major upgrade from voting on jerseys…

2 days ago

Shein Hits Wall Street and the Blockchain on the Same Day With $SHEINx

Shein's long-awaited public debut didn't stop at the Hong Kong Stock Exchange. Just hours after…

2 days ago

Hyperliquid Eyes U.S. Breakthrough Through Kraken Parent’s Regulated Derivatives Platform

Hyperliquid could finally be coming to America — but not by opening its decentralized exchange…

2 days ago