A critical security flaw in Zilliqa's Ledger hardware wallet app, dormant for seven years, has been actively exploited. The bug allowed attackers to recover users' private keys from public on-chain data.
Zilliqa detected the exploitation on July 19th and suspended all native ZIL transactions two days later. The vulnerability existed in how the Ledger app generated nonces for transaction signatures, making part of the cryptographic data predictable.
This is a software issue specific to the Zilliqa-Ledger companion app. The core Zilliqa blockchain and Ledger's hardware security are not affected. EVM-compatible transactions through Ledger also remain secure.
South Korean exchange Upbit has halted ZIL deposits and withdrawals. Zilliqa is collaborating with Ledger on a fix, but native transactions will remain suspended until a patched app is verified.
Users are advised not to move funds from any Ledger device holding ZIL. Compromised keys must be retired entirely, not transferred, as attackers could front-run any transaction attempt.