Zilliqa suspended native transactions after a Ledger flaw exposed private keys, while Upbit flagged ZIL as a cautionary asset globally.
Zilliqa has suspended native transactions after discovering a critical Ledger app vulnerability. Meanwhile, this flaw revealed private keys and prompted immediate response from major cryptocurrency exchanges.
Zilliqa Freezes Native Transactions Following Critical Ledger Vulnerability
The issue affected every Zilliqa Ledger app version released between 2019 and 2026. Furthermore, developers said that the vulnerability was being actively exploited by attackers since July 19.
Related reading: Thailand Investigates Large USDT Transactions Amid Money Laundering Concerns | Live Bitcoin NewsÂ
The issue was with the generation of the wrong nonce in the Ledger app, Zilliqa said. As a result, transaction signatures revealed enough information to reveal private keys over time.
Each nonce should be different for each blockchain transaction. But the Zilliqa Ledger app set a portion of the nonce to zero.
As a result, the application’s randomness became predictable and significantly weakened transaction security. Thus, the attackers would be able to study public signatures and get wallet credentials.
It was reported that approximately 5 native transactions were sufficient to reveal a private key. Moreover, the calculations could be carried out by an ordinary computer in just a few seconds.
Users affected by these wallets on their Ledger should immediately cease using compromised addresses, Zilliqa said. Furthermore, the private keys can never be secured again as signatures are always public and will stay on-chain forever.
While engineers worked on a permanent solution, the network suspended all native transactions. But EVM transactions are unaffected and still running on the Ethereum Virtual Machine throughout the ecosystem.
Upbit Flags ZIL as Exchanges Suspend Deposits and Withdrawals
South Korea’s exchange Upbit listed ZIL as an asset to be watched. As a result, the exchange halted all deposits and withdrawals on both trading markets, KRW and BTC.
Upbit also stated that the trading support may be terminated if Zilliqa does not solve the problem. As a result, the development team is under increasing pressure from users and exchanges all over the world.
Meanwhile, other exchanges responded quickly to the security incident. To ensure the safety of Binance and KuCoin’s customers, the deposit and withdrawal of ZIL on both platforms were temporarily suspended. Binance and KuCoin temporarily paused ZIL deposits and withdrawals to safeguard customer funds, as requested by Zilliqa.
The first alert came when a partner of the exchange spotted the theft of ZIL tokens. Investigators then traced the theft back to Ledger-generated private keys in native transactions.
News of the vulnerability prompted a swift market response. Consequently, ZIL has dropped around 10% and is currently trading around $0.0024 in recent trading sessions.
However, the incident serves as a reminder of the need to audit hardware wallet integrations regularly. Smaller blockchain ecosystems might be more vulnerable when vulnerabilities are not detected for long periods of time.
In addition, Zilliqa urged users to generate new wallets for themselves before transferring any assets. In the meantime, community members are still waiting for updates on when native transaction support will be restored throughout the network and for all the required security audits to be done going forward.
Meanwhile, the Zilliqa incident may serve as a catalyst for more comprehensive security audits in the crypto sector. In the meantime, investors will be watching closely how the network recovers and how future exchanges will be made across the world.





Leave a Reply
You must be logged in to post a comment.