Zilliqa Blames 683M ZIL Theft on 7-Year Ledger Bug
The 683M ZIL figure gets the headline, but the seven-year survival of the bug inside a Ledger-signed application is the real read for any token still relying on native hardware-wallet signing.
Every Zipp story tagged #HardwareWallet, newest first.
The 683M ZIL figure gets the headline, but the seven-year survival of the bug inside a Ledger-signed application is the real read for any token still relying on native hardware-wallet signing.
The bug was structural rather than random: a feature flag treated as present let attackers reconstruct private keys from a single button press, and Coinkite says severe losses have occurred even…
The patch tightens the RNG and signing flow, but seeds from affected firmware between 2021 and July 2026 still need replacement. AI-assisted auditing is the broader industry signal here.
The $100M in physical theft is the headline; the 40,000-record breach is the structural warning. Hardware-wallet security now means controlling what sits behind the device, not just the device itself.
The bug sat in open-source code for five years while a community built on 'don't trust, verify' outsourced its judgment to one vendor's reputation, Foundation CEO Zach Herbert argues.
Private keys and seed phrases are untouched, but names, physical addresses and contact details are now in the wild, giving attackers a clean phishing dataset that will linger well past the patch.
Galaxy Research has traced 1,596 BTC stolen across three confirmed attack waves, with a suspected fourth wave that would push total losses to roughly 2,000 BTC.
Roughly $38M has been swept from single-sig seeds generated between 2021 and 2023, and the exploit is unpatchable by design: any firmware fix would tip off attackers to wallets still holding funds.
The seed-randomness flaw had lurked in firmware since March 2021 and went unnoticed for years, exposing the practical ceiling of single-device self-custody for serious BTC holders.
Nearly 1,200 addresses and 1,000 BTC later, the incident has crossed from isolated phishing to a coordinated drain, putting self-custody users on notice about supply-chain risk in hardware wallets.
A three-year gap between Coldcard's final Mk3 firmware and the advisory turns dormant cold-storage wallets into a maintenance liability, with one signature and no passphrase as the worst-case custody…
The $38M theft from a single compromised wallet makes this the largest hardware-wallet supply-chain attack on record, with Coldcard pointing users straight at a firmware load-bearing weakness.
Crypto sat out the sharpest equity rebound of the year, with BTC holding $64,300 even as a $38M Coldcard wallet exploit swept 594 bitcoin off-chain without moving the tape.
The single-signature wallets swept had been dormant for years, but the underlying firmware bug has been live since March 2021, with paper wallet keys and seed-splitting masks exposed too.
Roughly 500 wallet addresses were drained in a pattern tied to a Mk3 firmware bug, putting the total stolen above $35M and forcing Coinkite to flag every device that ever generated a seed on 4.0.1 or…
The flaw lets private keys be recovered from any affected onchain signature; EVM transactions and SDKs are unaffected, narrowing the blast radius.
The defining gap is the backup model: DCENT S issues a non-signing R3covery Card, while Tangem duplicates full-signing cards, a trade-off between segmented security and immediate redundancy.
Transaction sign-off stays on a physical device, so an autonomous agent can read balances and draft swaps but can never broadcast one without a human tap.
The open-source toolkit lets AI agents read balances and prepare transactions, but every sensitive action still needs physical approval on a Ledger device.
Both vendors agree the bug is real on a lab bench; Tangem argues it stays academic because resetting the PIN needs a laser, the card in hand, and rare know-how.