Zilliqa Ledger app bug allowed private key recovery, Upbit flags ZIL
Security & Exploits ·
A nonce-generation flaw in Zilliqa's Ledger app let attackers recover private keys from public signatures, prompting Upbit to mark the token cautionary and suspend deposits and withdrawals.
Zilliqa disclosed that a critical flaw in its Ledger app's nonce generation could expose private keys after roughly five native transactions were signed, since the flawed process leaked enough information from repeated signatures to reconstruct the underlying key. The vulnerability affected every version of the app released between 2019 and 2026, and active exploitation was observed on July 19, according to wublockchain.xyz. In response, native transactions on the network have been suspended and affected keys must be retired, while EVM transactions are described as unaffected.
The bug traces back to Zilliqa's Ledger integration dating to 2019, according to theblock.co, which reported that the network halted native transactions over the issue. Separate commentary circulating on the flaw's timeline placed the underlying vulnerability's origin in August 2019, per a post referenced at x.com, consistent with the broader window Zilliqa itself cited for affected versions.
Upbit designated ZIL a cautionary asset across its KRW and BTC markets following the disclosure. Deposits and withdrawals on the exchange remain suspended, and Upbit has indicated that trading support could be terminated if the underlying issue is not resolved.
Four distinct sources are tracking the disclosure, with consistent details on the 2019-origin bug and the native-transaction halt, though descriptions vary slightly between framing the flaw as newly disclosed versus a long-standing issue only now surfaced.
What remains unclear is the scope of keys already compromised before the July 19 exploitation was detected, whether any funds were moved using recovered keys, and what remediation Zilliqa will require before native transactions and Upbit's trading support are restored.