TL;DR
- Zilliqa suspended native ZIL transactions after discovering a critical vulnerability in its Ledger app that has existed since 2019.
- The bug affects Schnorr signature generation and allows private keys to be recovered from public on-chain data with five or more compromised signatures.
- EVM transactions and the network’s own SDKs are not affected; KuCoin collaborated in identifying the root cause and confirming the exploit.
Zilliqa suspended its native ZIL transactions after detecting a critical vulnerability in its application for Ledger devices that had remained hidden since 2019. The flaw allows the private keys of affected users to be recovered from publicly available signatures on the chain, posing a direct risk to the funds of those who have signed native transactions with the Ledger hardware.
According to a statement published by the team, the issue resides in the generation of Schnorr signatures for native Zilliqa transactions. The signing routine copied 32 incorrect bytes from a 40-byte value, leaving the most significant 64 bits of each ephemeral nonce fixed at zero. That reduction in cryptographic randomness makes it possible to reconstruct a private key from approximately five or more affected signatures using publicly available blockchain data.
Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated… https://t.co/sudV7WA3TV
— Zilliqa (@zilliqa) July 22, 2026
Zilliqa Is Actively Working on Solutions
The team detected on-chain activity consistent with an active exploit on July 19 and identified the root cause two days later. By that point, protective measures had already been implemented to prevent further losses. At the same time, a coordinated remediation plan is being finalized and a corrected version of the Zilliqa app for Ledger is being prepared in conjunction with the device manufacturer, although the launch date has not yet been announced.
The team indicated that users who have signed native transactions with a Ledger device should await official instructions before taking any action. Those who operate with ZIL exclusively through EVM-compatible tools are not exposed to the vulnerability.
KuCoin’s Collaboration Was Key
In the statement, the Zilliqa team highlighted the collaboration of exchange KuCoin, crediting it with having helped identify the root cause of the nonce generation flaw, recover affected private keys from public on-chain data and confirm that the vulnerability was being actively exploited.
The coordination with the platform, according to the team, was key to implementing the protective measures while the remediation plan was being developed.







