Zilliqa suspended native transactions after disclosing a bug in its Ledger app dating to 2019 that allows private keys to be recovered from affected onchain signatures.
The flaw affects native ZIL transactions signed with Ledger devices. EVM transactions and Zilliqa SDKs remain unaffected, which narrows the blast radius to a specific signing path rather than the broader Zilliqa stack.
Why it matters
A private-key recovery flaw in a hardware wallet integration is the worst category of bug for that device class: the whole pitch of a hardware wallet is that the key never leaves the secure element. If an attacker can reconstruct a private key from a single signature, every past and future signature from the same device is exposed. The fact that the flaw has sat in the Ledger app since 2019 means a multi-year window of signatures may now be retroactively attackable, not just newly generated ones.
Market impact
Zilliqa's native halt is the operational response: pause signing, stop new transactions, force a fix before users sign again. Holders should treat any ZIL address that ever signed a native transaction on a Ledger as compromised until the patched app ships and keys are migrated. The episode is also a reminder that supply-chain bugs in wallet integrations can outlive multiple firmware cycles and only surface when someone actually audits the recovery path.
Frequently asked questions
-
What did Zilliqa disclose about its Ledger app?
Zilliqa disclosed a bug in its Ledger app dating to 2019 that allows private keys to be recovered from affected onchain signatures, and suspended native transactions in response.
-
Are EVM transactions on Zilliqa affected by the bug?
No. The flaw affects native ZIL transactions signed with Ledger devices, while EVM transactions and Zilliqa SDKs remain unaffected.
-
How long has the Ledger app vulnerability been present?
The bug dates to 2019, meaning affected devices may have been exposing recoverable private keys from onchain signatures for roughly six years.
-
What should Zilliqa users with Ledger devices do?
Treat any ZIL address that ever signed a native transaction on a Ledger as compromised until the patched app ships, then migrate funds to a fresh address with a new key.
-
Why is a key-recovery flaw so serious for hardware wallets?
The core promise of a hardware wallet is that the private key never leaves the secure element. A flaw that reconstructs the key from a single signature invalidates that guarantee and exposes every past and future signature from the device.
TheBlock