Zilliqa Halts Native Transactions Due to Ledger App Key-Recovery Bug

iconNS3
Share
AI summary iconSummary
Zilliqa paused native transactions after identifying a Ledger app key-recovery bug, per on-chain news. The flaw, reported by KuCoin, could let attackers rebuild private keys from signatures. Zilliqa said the issue impacted Ledger app versions from 2019 to 2026. The problem was found on July 19, with confirmation on July 21. EVM transactions and SDK signing remain unaffected. KuCoin news highlighted the role of the exchange in alerting the project.

Key Point

Zilliqa suspended native, non-EVM transactions after discovering a Ledger app signing flaw that may let attackers reconstruct a private key from roughly five affected signatures. Zilliqa said every version of the Zilliqa Ledger app released between 2019 and 2026 contained the flaw. Zilliqa detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. The disclosure did not identify affected addresses or quantify any losses. Zilliqa credited KuCoin with reporting the incident and helping confirm the vulnerability. Zilliqa said EVM transactions and official SDK signing paths are unaffected.

Why it matters: A wallet-signing flaw can turn past on-chain activity into a live key-compromise risk, which may disrupt transfers until safe migration is available.

Market Sentiment

Cautiously Bearish, Stress-on, Tech-driven.

Reason: Zilliqa suspended native transactions after identifying an actively exploited Ledger app signing flaw, so users may treat the event as direct infrastructure stress.

Similar Past Cases

In 2020, IOTA expected to reactivate its network by March 2 after a $2M user-wallet attack tied to Trinity wallet software. (The Block) Difference: the Zilliqa disclosure did not quantify losses and centers on exposed signatures from Ledger app native transactions.

Ripple Effect

A native-transaction pause can concentrate user activity in unaffected paths until migration instructions become clear. If Zilliqa publishes a migration procedure and native transactions reopen without fresh exploit activity, then spillover may remain mostly contained to Zilliqa users. If attackers compete with legitimate holders after reopening, then confidence in affected signing paths may weaken.

Opportunities & Risks

Opportunities: When Zilliqa publishes official migration instructions and the corrected Ledger app release, then confirmed safe migration is a potential reentry signal. Waiting for confirmation before adding exposure limits rescue-transfer risk.

Risks: If native transactions reopen before holders can retire affected keys safely, then reducing exposure limits downside from front-running risk. If Zilliqa keeps the reopening date undisclosed, then staying hedged reduces event-risk exposure.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.