The Latest Crypto News
Tuesday, 28 July 2026 BTC -- / --
🔍

Critical vulnerability in Zilliqa Ledger app exposes private keys

Make The Latest Crypto News preferred on Google
Zilliqa coin and Ledger hardware wallet with a red warning symbol over a cracked key
Zilliqa coin and Ledger hardware wallet with a red warning symbol over a cracked key

Zilliqa has disclosed a critical vulnerability in the official Ledger app that has been present in every release since 2019. Due to an error in nonce generation when signing native Zilliqa transactions, attackers can reconstruct a user’s private key from publicly available data on the blockchain. Accounts that have signed five or more native transactions via the Ledger app should be considered compromised.

How the vulnerability works

Native Zilliqa transactions use EC-Schnorr signatures over secp256k1. Each signature requires a random 256-bit nonce. In the Ledger app, the signing code generated 40 bytes of randomness, but when copying to the nonce buffer, the wrong 32 bytes were selected. As a result, eight bytes of zeros remained and eight bytes of entropy were lost. The consequence: the 64 most significant bits of every nonce were always zero.

With five or more signatures exhibiting this pattern, it is possible to recover the private key within seconds on ordinary hardware using so-called lattice reduction. Because the affected transactions are permanently on the blockchain, a software update does not resolve the issue for existing accounts. Those keys must be decommissioned.

On 19 July 2026, active exploitation was observed on the blockchain. Two days later, the cause was confirmed by reproducing the problem based on existing signatures. According to Zilliqa, KuCoin played a central role in identifying the cause, reconstructing affected private keys, and promptly reporting the active exploitation. Read more about hacks and exploits in the crypto world in our overview.

Suspended transactions and consequences for ZIL

As an immediate measure, Zilliqa has suspended all native transactions to limit further damage. EVM transactions are unaffected, as are the official software development kits such as zilliqa-js, gozilliqa-sdk and pyzil. Users who manage ZIL solely via EVM-compatible tools are not at risk.

The South Korean exchange Upbit reports Upbit that ZIL has been designated a warning asset on both the KRW and BTC markets. Deposits and withdrawals remain suspended, and the exchange states that it may terminate trading support if the issue is not resolved. Zilliqa urges users not to take independent action and to follow only the official channels for further instructions on securing affected funds.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Altcoin News

More news ›