Zilliqa has temporarily suspended all native ZIL transactions after discovering a critical vulnerability in its Ledger hardware wallet application that dates back to 2019. The flaw could allow attackers to reconstruct users’ private keys from publicly available blockchain signatures, potentially giving them access to affected wallets. While the issue impacts only native ZIL transactions signed through the legacy Ledger app, Zilliqa emphasized that its blockchain, Zilliqa 2.0, EVM-compatible transactions, and developer SDKs remain secure.
The network acted quickly by pausing native transactions and coordinating with Ledger to develop a patched application before additional users could be affected. The incident follows reports of an exchange cold wallet compromise linked to the vulnerability and serves as another reminder that wallet software can introduce security risks even when the underlying blockchain remains uncompromised.
According to Zilliqa, the vulnerability existed in every released version of its native Ledger application since 2019.
The flaw:
Because blockchain signatures are permanently stored on-chain, any vulnerable signatures created over the past several years remain publicly accessible.
To prevent further exploitation, Zilliqa
The emergency response included:
The network said normal operations will resume after the updated Ledger application has been fully deployed.
The project stressed that the vulnerability does not affect the underlying blockchain itself.
According to the team:
This distinction is important because the issue originated in wallet software rather than the blockchain’s consensus mechanism or smart contract infrastructure.
Developers warned users not to move funds until remediation instructions are released.
Users who:
may need to migrate assets to newly generated wallets after official recovery procedures become available.
The team said additional guidance will be published once the patched Ledger application has completed testing.
The vulnerability came to light after Zilliqa identified suspicious activity involving a cold wallet belonging to one of its exchange partners.
While the project has not publicly identified the exchange or disclosed the amount stolen, investigators determined that the compromise was connected to the long-standing Ledger application bug, prompting the immediate suspension of native transactions.
Security teams continue monitoring affected wallets while coordinating with exchanges and infrastructure providers.
Although Ledger hardware wallets are widely regarded as one of the safest methods for storing cryptocy, the incident highlights that vulnerabilities can still arise through wallet applications.
Even when private keys never leave a hardware device, flawed cryptographic implementations can weaken transaction signatures and expose users to attacks if software is improperly designed.
Russian President Vladimir Putin has signed a landmark cryptocy law establishing the country's first comprehensive regulatory…
Coinbase has launched 24-hour, five-day-a-week trading for nearly 4,000 U.S. stocks for eligible customers in the United Kingdom, marking another major…
Shaw Walters, founder of Eliza Labs, has declared the project's native ELIZA token "dead" and confirmed that the Eliza…
The Web3 fitness platform Step App has announced it will permanently shut down after four years in…
The Digital Asset Market CLARITY Act is running out of time in the U.S. Senate as lawmakers scramble to…
Cloudflare has unveiled Cloudflare Wallets, a new programmable stablecoin wallet system that allows AI agents to independently pay for…