
Zilliqa has paused native, non-EVM transactions after finding a flaw in its Ledger app that can let attackers recover a private key from public signatures. For users who signed native Zilliqa transactions with a Ledger device, the risk is serious because signatures already posted on-chain may be enough to expose the key.
According to Zilliqa, every version of the app released from 2019 to 2026 carried the bug. The issue affects Schnorr signatures used for native transactions only. EVM transactions are not affected, and the signing paths in zilliqa-js, gozilliqa-sdk, and pyzil are outside the disclosed flaw.
The problem came from how the app generated the nonce for each signature. An error kept eight zero-padding bytes and dropped eight bytes of real entropy, making the nonce far weaker than intended. Zilliqa said an attacker can combine about five affected signatures from the same private key and reconstruct that key within seconds on standard hardware.
The network said it saw on-chain activity consistent with exploitation on July 19 and confirmed the cause on July 21. KuCoin reported the issue and helped trace it. Zilliqa is preparing a fix with Ledger, but that update will only protect future signatures. Users who signed native transactions with Ledger have been told to wait for official migration instructions, since a normal rescue transfer could be front-run by an attacker using the same recovered key.
◆ Source
Originally published by CryptoSlate on July 24, 2026.
◆ Linked coin (1)
◆ Build with us
Every event, verified and scored. One API call away.


