Zilliqa halted native ZIL transactions after a Ledger hardware wallet bug dating to 2019 exposed users' private keys through onchain signatures.
"The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key," Zilliqa said in a Wednesday post on X.
Exploitation began July 19. A day later, an exchange partner reported ZIL stolen from a cold wallet. KuCoin helped trace the bug, which was confirmed July 21. Any account that broadcast at least five native ZIL transactions through the Ledger app should be considered compromised, Zilliqa said. The flaw affected every version of the app since Zilliqa's 2019 mainnet launch.
ZIL traded near $0.0025 as of Wednesday, down 17% over the past week and 99% from its May 2021 peak. Upbit placed ZIL on delisting watch under Korea's Virtual Asset User Protection Act, with a review running through the week of Aug. 17. Zilliqa said it will publish a corrected app version in coordination with Ledger and has promised a recovery plan for affected balances.
EVM-compatible transactions and software wallets were not affected by the vulnerability, Zilliqa said. Native ZIL deposits and withdrawals remain suspended on exchanges including Upbit, which froze them July 20. The exchange's risk label covers the ZIL/KRW and ZIL/BTC trading pairs.
The incident joins a string of key compromise attacks this year. Zilliqa's market cap stood at about $49 million, according to CoinMarketCap data. The token hit a record low of $0.00235 on Wednesday.
Zilliqa said protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized. Affected keys must be retired because the leaked signatures remain on-chain permanently.
This article is for informational purposes only and does not constitute investment advice.