Zilliqa suspended native ZIL transfers on July 22 after confirming a long-standing flaw in the Ledger app used for certain transactions could allow private keys to be reconstructed from public signature data. The issue affects native, non-EVM ZIL transfers signed on Ledger hardware and prompted the network to tell affected users not to move funds while a fix is prepared.

Flaw traced back to 2019

According to Zilliqa, the bug has existed since 2019 in the Ledger app’s handling of Schnorr signatures for native ZIL transactions. A 32-byte copy error reportedly caused the signing nonce to lose randomness by fixing the top 64 bits at zero. That weakness meant signatures published on-chain could reveal enough information for an attacker to recover a user’s private key.

Zilliqa said roughly five or more affected signatures may be sufficient for key reconstruction using only public on-chain data. Because the flaw dates back several years, any qualifying native ZIL transactions signed with a Ledger device since 2019 may be exposed.

What is and is not affected

The project said the vulnerability is limited to native ZIL transfers signed on Ledger hardware. It does not affect EVM transactions, and users who handled ZIL only through EVM-compatible tools or through Zilliqa SDKs are not considered exposed under the current guidance.

That distinction is central to the incident response. Zilliqa’s freeze applies to native transfers as the team works to contain the risk tied specifically to signatures generated by the affected Ledger app.

Exploitation concerns and response

Zilliqa said KuCoin helped confirm that the flaw was being actively exploited. In response, the network put protective measures in place and halted native ZIL movements while Ledger finalizes an updated application.

The team advised holders who previously signed native ZIL transactions with a Ledger device to wait for official instructions rather than attempt to move funds. Ledger is developing a patched version of the app, though Zilliqa said the timing for its release would be announced later.

Market backdrop

The suspension comes with ZIL trading near an all-time low of about $0.0024, according to the source report. While the price level provides market context, the immediate issue is operational and security-related: a signature-generation defect that, under certain conditions, can expose wallet keys through already public blockchain data.

The episode highlights how a narrowly scoped implementation bug in wallet software can create broad risk when it persists for years and affects signatures recorded on-chain. For now, Zilliqa’s guidance remains focused on limiting further exposure for users of native ZIL transfers on Ledger devices until the patched app and additional instructions are released.

Source: Cryptopolitan