Tech

Zilliqa Halts Native Transactions After Discovering Critical Ledger Wallet Bug Dating Back to 2019

Zilliqa has temporarily suspended all native ZIL transactions after discovering a critical vulnerability in its Ledger hardware wallet application that dates back to 2019. The flaw could allow attackers to reconstruct users’ private keys from publicly available blockchain signatures, potentially giving them access to affected wallets. While the issue impacts only native ZIL transactions signed through the legacy Ledger app, Zilliqa emphasized that its blockchain, Zilliqa 2.0, EVM-compatible transactions, and developer SDKs remain secure.

The network acted quickly by pausing native transactions and coordinating with Ledger to develop a patched application before additional users could be affected. The incident follows reports of an exchange cold wallet compromise linked to the vulnerability and serves as another reminder that wallet software can introduce security risks even when the underlying blockchain remains uncompromised.

Critical Ledger Bug Exposed Private Keys

According to Zilliqa, the vulnerability existed in every released version of its native Ledger application since 2019.

The flaw:

  • Affected native ZIL transactions signed with Ledger devices.
  • Generated predictable cryptographic signing nonces.
  • Allowed attackers to recover private keys using publicly available on-chain signatures.
  • Required approximately five or more affected signatures to reconstruct a private key.

Because blockchain signatures are permanently stored on-chain, any vulnerable signatures created over the past several years remain publicly accessible.

Native Transactions Temporarily Suspended

To prevent further exploitation, Zilliqa immediately halted native network transactions.

The emergency response included:

  • Suspending native ZIL transfers.
  • Coordinating with Ledger on a patched wallet application.
  • Working with exchanges to pause deposits and withdrawals where necessary.
  • Launching a coordinated remediation plan for affected users.

The network said normal operations will resume after the updated Ledger application has been fully deployed.

Zilliqa 2.0 and EVM Transactions Remain Safe

The project stressed that the vulnerability does not affect the underlying blockchain itself.

According to the team:

  • Zilliqa 2.0 remains secure.
  • EVM-compatible transactions are unaffected.
  • Zilliqa SDKs were not impacted.
  • Only the legacy native Ledger application contains the vulnerable signing implementation.

This distinction is important because the issue originated in wallet software rather than the blockchain’s consensus mechanism or smart contract infrastructure.

Users Urged to Wait for Official Guidance

Developers warned users not to move funds until remediation instructions are released.

Users who:

  • Signed native ZIL transactions using Ledger devices.
  • Generated multiple historical signatures.
  • Used the vulnerable Ledger application since 2019.

may need to migrate assets to newly generated wallets after official recovery procedures become available.

The team said additional guidance will be published once the patched Ledger application has completed testing.

Exchange Theft Triggered Investigation

The vulnerability came to light after Zilliqa identified suspicious activity involving a cold wallet belonging to one of its exchange partners.

While the project has not publicly identified the exchange or disclosed the amount stolen, investigators determined that the compromise was connected to the long-standing Ledger application bug, prompting the immediate suspension of native transactions.

Security teams continue monitoring affected wallets while coordinating with exchanges and infrastructure providers.

Hardware Wallet Software Can Still Create Risk

Although Ledger hardware wallets are widely regarded as one of the safest methods for storing cryptocy, the incident highlights that vulnerabilities can still arise through wallet applications.

Even when private keys never leave a hardware device, flawed cryptographic implementations can weaken transaction signatures and expose users to attacks if software is improperly designed.

Terron Gold

Recent Posts

Putin Signs Landmark Crypto Law Legalizing Regulated Retail Trading in Russia

Russian President Vladimir Putin has signed a landmark cryptocy law establishing the country's first comprehensive regulatory…

6 days ago

Coinbase Brings 24/5 U.S. Stock Trading to UK Users as It Builds an Everything Exchange

Coinbase has launched 24-hour, five-day-a-week trading for nearly 4,000 U.S. stocks for eligible customers in the United Kingdom, marking another major…

1 week ago

Eliza AI Founder Declares Token Dead as Foundation Shuts Down After Lawsuit Settlement

Shaw Walters, founder of Eliza Labs, has declared the project's native ELIZA token "dead" and confirmed that the Eliza…

1 week ago

Step App Shuts Down After Four Years as FITFI Token Collapses to Near-Zero Market Cap

The Web3 fitness platform Step App has announced it will permanently shut down after four years in…

1 week ago

CLARITY Act Faces Critical Senate Deadline as Lawmakers Race Against August Recess

The Digital Asset Market CLARITY Act is running out of time in the U.S. Senate as lawmakers scramble to…

1 week ago

Cloudflare Launches Stablecoin Wallets Giving AI Agents the Ability to Pay Across the Internet

Cloudflare has unveiled Cloudflare Wallets, a new programmable stablecoin wallet system that allows AI agents to independently pay for…

1 week ago