
Zilliqa has paused native ZIL transfers after a Ledger app flaw affecting native signatures, while an earlier exchange-partner cold-wallet theft and renewed price pressure have added to scrutiny around the token.
Zilliqa has suspended native ZIL transactions after disclosing a critical flaw in its Ledger app that can let attackers recover private keys from public signatures tied to native, non-EVM transactions. The network said the bug dated back to 2019 and stemmed from a nonce-generation error in Schnorr signatures that left the top 64 bits fixed at zero, allowing a private key to be reconstructed from about five or more affected signatures using public on-chain data. Zilliqa said it detected on-chain activity consistent with exploitation on July 19, found the root cause on July 21 and disclosed it on July 22, with KuCoin helping identify the nonce bug and retrieve affected private keys from public signatures. The project said it has taken protective measures and that Ledger is working on a patched app, while users who signed native ZIL transactions with Ledger devices have been told to wait for official guidance rather than move funds. The issue does not affect EVM transactions or Zilliqa SDK-based signing. The disclosure came days after Zilliqa said ZIL had been stolen from an exchange partner’s cold wallet, an incident it has not linked to the Ledger flaw. ZIL was down 3.5% over 24 hours to $0.00244, near the $0.002441 all-time low reported after the earlier theft, according to CoinGecko data.