Loading prices…
🩸BEARISH

ZIL Ledger Flaw Exposes Keys as Upbit Flags Risk

A nonce-reuse bug in the Zilliqa Ledger app let attackers reconstruct private keys from roughly five native signatures, and Upbit's cautionary-asset designation now puts ZIL trading support itself in…

Zilliqa disclosed a critical vulnerability in its official Ledger app that allows private keys to be reconstructed from publicly visible signatures after roughly five native transactions. The bug, a nonce-generation flaw traced through every Ledger app release from 2019 to 2026, was actively exploited on July 19, with Zilliqa suspending native transactions and telling affected users to retire exposed keys. EVM-based ZIL transactions are unaffected.

Why it matters

The flaw is severe by construction: any deterministic, observable signature that lets an attacker narrow the private key by a meaningful fraction becomes a full key recovery once the budget is met. Five transactions is a low bar to cross for any wallet that has signed natively since 2019. Hardware-wallet users typically trust the device precisely because the seed never leaves it, so a vulnerability that bleeds the seed through on-chain signatures erodes the core promise of cold storage for this specific integration.

Market impact

Upbit, South Korea's largest exchange by volume, designated ZIL a cautionary asset on its KRW and BTC markets, suspending deposits and withdrawals and reserving the right to terminate trading support if the underlying issue is not resolved. The move isolates liquidity for a token whose native-transaction path is already frozen, and it lands alongside reports of in-the-wild exploitation. Holders who relied on the Ledger integration for native ZIL custody now face a forced migration, and the cautionary tag signals that venue-level support is contingent on a fix rather than guaranteed.

Source: [질리카(ZIL) 거래 유의 종목 지정 안내 — 업비트(Upbit)](https://www.upbit.com/service_center/notice?id=469118962&view=share)

Related tokens
$ZIL

Frequently asked questions

  1. What is the Zilliqa Ledger app vulnerability?

    A nonce-generation flaw in Zilliqa's official Ledger app allows attackers to reconstruct private keys from publicly visible signatures after roughly five native transactions, affecting all releases from 2019 to 2026.

  2. Is user funds at risk from the Zilliqa Ledger flaw?

    Yes for native ZIL keys signed on affected Ledger app versions since 2019. Zilliqa suspended native transactions and told users to retire exposed keys; EVM ZIL transactions are unaffected.

  3. Has the Zilliqa Ledger vulnerability been exploited?

    Zilliqa confirmed active exploitation on July 19, with attackers able to recover private keys after observing roughly five native signatures on affected versions.

  4. Why did Upbit flag ZIL as a cautionary asset?

    Upbit designated ZIL a cautionary asset across its KRW and BTC markets after the Ledger vulnerability disclosure, suspending deposits and withdrawals and warning that trading support may be terminated if the issue is not resolved.

  5. What should ZIL holders do after the Ledger flaw disclosure?

    Holders who signed native ZIL transactions on the Ledger app since 2019 should treat the key as compromised and migrate funds to a fresh key path, since affected keys cannot be remediated in place.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 1h ago
Open original →