Zilliqa Halts Native Transactions After Major Ledger App Bug
A seven year old security flaw in the Zilliqa Ledger app allowed attackers to rebuild private keys from just five signatures.

ZILcoinbeat.news
ZIL/USD live chart
LIVEZilliqa has suspended native transactions following the discovery of a critical security vulnerability affecting its Ledger app. Every version of the app released between 2019 and 2026 contained a flaw in the nonce generation code, which reduced the entropy of native signatures. This weak randomness meant that attackers could combine roughly five affected signatures from the same private key and reconstruct that key within seconds using standard computer hardware.
The project detected suspicious on chain activity on July 19 and confirmed the root cause two days later. Because the vulnerable signatures are permanently recorded on the blockchain, updating the software cannot protect keys that have already been exposed. Accounts with five or more native transactions signed through the affected Ledger app are considered compromised and must eventually retire their private keys.
Moving funds safely presents another challenge because attackers who already hold the private key can attempt to front run any rescue transfer. Zilliqa is currently finalizing a coordinated recovery plan to allow safe asset migration before reopening native transactions. The team advises affected users to wait for official instructions, while confirming that EVM transactions and official software development kits remain completely secure.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



