Binance will migrate ZIL held on its platform from Zilliqa’s legacy mainnet to Zilliqa EVM on a 1:1 basis, taking care of the technical process for users. The move comes as Zilliqa shuts down its older transaction system after a security flaw tied to its Ledger application exposed thousands of accounts.
ZIL trading on Binance is set to continue without interruption during the migration. Deposits and withdrawals on the legacy Zilliqa network have been suspended since Aug. 5 at 01:00 UTC, and once Binance completes the transition it plans to reopen transfers through Zilliqa EVM, without a separate launch notice.
Binance ends support for the old Zilliqa network
Under Binance’s plan, balances currently linked to legacy Zilliqa mainnet addresses will be moved to the EVM network at a 1:1 ratio. After that change, the exchange will no longer support deposits or withdrawals through the older network.
Binance said the migration will not disrupt spot trading, margin trading, futures or Binance Earn products involving ZIL. The announcement also places Binance alongside other platforms moving away from Zilliqa’s legacy Schnorr-based transaction system as the blockchain retires that infrastructure.
Ledger app flaw drove the emergency migration
Zilliqa traced the broader migration effort to a vulnerability in its Ledger application affecting native, non-EVM transactions signed on Ledger devices. According to the project’s post-mortem, the issue weakened Schnorr signatures by leaving the top 64 bits of each nonce fixed at zero, making it possible in some cases to reconstruct a private key from several public signatures tied to the same account.
Zilliqa said the flaw existed in every released version of the Ledger application from 2019 through 2026. The first confirmed theft was dated March 4, while unusual activity increased in July. KuCoin alerted Zilliqa on July 19 after spotting suspicious outgoing transfers from a cold wallet, and Zilliqa disabled legacy transactions on July 20 before identifying the root cause the next day.
The project later said at least 683.13 million ZIL had been stolen across 66 transactions. It identified 6,772 exposed accounts and 51 drained accounts, while stressing that both figures remain minimum confirmed totals and that additional exposed accounts could still be found.
Balances are being reassigned to EVM addresses
Zilliqa concluded that patching the Ledger app would not be enough to protect wallets whose private keys may already have been exposed through signatures permanently recorded onchain. It therefore chose to retire the non-EVM transaction system and reassign balances at the protocol level from legacy addresses to EVM addresses.
The exchange migration has been carried out in stages, because each platform has had to submit and verify its EVM wallet addresses before balances could be reassigned. A first migration hard fork on Sept. 2 covered exchanges including KuCoin, MEXC, OKCoin, Binance US, Bitvavo, Korbit, Indodax, Bitrue, WhiteBIT, CoinSpot and CoinSwitch. A second hard fork was scheduled for Sept. 22 for another group that included CoinEx, HTX, Bitkub, GOPAX, Coinone, OKX, LBank, Crypto.com, Gate, Paribu, CEX.IO and Bitget.
Binance had not been included in those earlier batches. Its latest decision confirms that it will also abandon the old network for deposit and withdrawal infrastructure and move to Zilliqa EVM.
Separate route for self-custody users and recovery efforts
Users holding ZIL in their own legacy wallets are not covered by exchange migrations. For them, Zilliqa has built a zero-knowledge-proof-based migration tool intended to let holders prove ownership of an old address and move the related balance to an EVM address without sharing a seed phrase or private key. The project said in a September update that the tool’s audit had been completed and internal testing was under way, with rollout targeted for Sept. 22 alongside an escrow contract needed for the process.
Zilliqa has warned users not to try moving funds with exposed legacy keys, since both an attacker and the legitimate owner could potentially sign from an account once the private key is reconstructed. For that reason, legacy transactions were disabled across the board, including for wallets not known to be exposed.
Balances already stolen in the incident are being handled separately and are not automatically returned through exchange migration hard forks. Zilliqa said it has been working with exchanges and law enforcement to trace the assets, and that an exchange account used to liquidate part of the stolen funds had been identified and frozen. The project also said it was working with Singapore Police and a law firm on recovery, while separately preparing a community governance proposal that could include token minting to compensate affected holders.
Zilliqa EVM becomes the sole production path
The shift to EVM infrastructure did not begin with the Ledger incident. Zilliqa moved to Zilliqa 2.0 in June 2025, adding full Ethereum Virtual Machine compatibility, proof-of-stake consensus and architectural changes after a six-month testing period that included 21 external validators, 7.5 million proto-mainnet blocks and 15 client upgrades.
Even after that transition, the chain continued to support its older native transaction system alongside the EVM environment. Zilliqa said the security incident accelerated a decision it had already been considering: fully retiring the legacy stack, which it described as a growing development and security burden, and making Zilliqa EVM the network’s only production environment.
Source: crypto.news