A nonce-generation defect present in every version of the Zilliqa Ledger application since 2019 allows an attacker to reconstruct a user's private key from approximately five native transaction signatures recorded on-chain. The flaw — a coding error that zeros the upper 64 bits of each Schnorr si...
"At this stage, we have found no evidence that the incident was caused by the exchange's wallet management or operational processes." — Zilliqa, Official Disclosure Statement
A nonce-generation defect present in every version of the Zilliqa Ledger application since 2019 allows an attacker to reconstruct a user's private key from approximately five native transaction signatures recorded on-chain. The flaw — a coding error that zeros the upper 64 bits of each Schnorr signature nonce — went undetected for seven years across all supported Ledger device models. Active exploitation was observed on July 19, 2026. Zilliqa suspended all native, non-EVM transactions on July 21 and publicly disclosed the vulnerability on July 22.
ZIL dropped approximately 19% over the week following disclosure, trading at $0.0024 with a market capitalization near $49 million. South Korea's Upbit, one of the highest-volume exchanges globally, designated ZIL as a cautionary asset, froze deposits and withdrawals, and initiated a delisting review through mid-August. KuCoin, which cooperated in identifying the vulnerability, restricted native ZIL transfers. Zilliqa has not disclosed the total value of funds stolen, stating only that an undisclosed amount was taken from an exchange partner's cold wallet.
The incident is notable not because of its dollar magnitude — Zilliqa's market cap places it outside the top 350 tokens — but because it exposes a class of cryptographic implementation error that persists across the industry: faulty nonce generation in digital signature schemes. The weakened signatures are permanently recorded on the blockchain. No software update can retroactively protect exposed keys.
The Zilliqa Ledger application generates Schnorr signatures for native (non-EVM) transactions. The signing routine correctly produced 40 bytes of randomness and reduced the result modulo the curve order to yield a uniform 32-byte nonce. However, when copying the reduced value into the signature buffer, the code selected the wrong 32-byte window — retaining eight zero-padding bytes from the modular reduction and discarding eight bytes of actual entropy.
The result: every nonce generated by the application had its highest 64 bits fixed at zero, constraining each value below 2^192 rather than spanning the full 2^256 range of the curve order. This reduced the effective entropy of every signature nonce by 25%.
The defect affected all released versions of the Zilliqa Ledger app across all supported Ledger devices — Nano S, Nano S Plus, Nano X, and Stax — from the initial 2019 release through July 2026. EVM-compatible transactions, the zilliqa-js SDK, gozilliqa-sdk, and pyzil SDK were not affected, as they use independent signing paths.
| Date | Event | |------|-------| | 2019 | Zilliqa Ledger app first released with nonce-generation flaw | | July 19, 2026 | On-chain activity consistent with active exploitation detected | | July 21, 2026 | Root cause confirmed; native (non-EVM) transactions suspended network-wide | | July 22, 2026 | Public disclosure issued; corrected Ledger app build prepared | | July 22-23, 2026 | Upbit designates ZIL as cautionary asset; deposits/withdrawals frozen | | July 22-23, 2026 | KuCoin restricts native ZIL transfers |
KuCoin played a central role in identifying the vulnerability. According to reports, the exchange recovered affected private keys from publicly available on-chain signature data and helped confirm that exploitation was ongoing. Zilliqa stated that an undisclosed amount of ZIL had been stolen from an exchange partner's cold wallet but provided no specific figure. The network stated it found "no evidence that the incident was caused by the exchange's wallet management or operational processes."
ZIL declined approximately 19% in the week following disclosure, trading at $0.0024 with a market capitalization of roughly $49 million. The token's circulating supply stands at approximately 20.1 billion ZIL out of a maximum supply of 21 billion.
Upbit's response was the most consequential. As the largest exchange in South Korea and one of the highest-volume venues globally, its designation of ZIL as a cautionary asset carries material weight. The exchange suspended deposits and withdrawals across its KRW and BTC markets for ZIL and opened a delisting review through mid-August 2026. Under South Korea's investor protection framework, the cautionary designation signals elevated risk; failure to resolve the underlying issue within the review period can result in trading termination.
KuCoin, which cooperated in identifying the vulnerability, restricted native ZIL transfers while EVM-compatible transactions continued to operate normally.
The native transaction suspension effectively froze one half of Zilliqa's dual-network architecture. The EVM-compatible side remained operational, but the inability to process native transactions locked out users who had not migrated to EVM tooling.
The attack exploiting Zilliqa's nonce flaw belongs to a well-documented class of cryptographic attacks. When a digital signature scheme produces nonces with known biased bits, an attacker can frame the recovery of the private key as an instance of the Hidden Number Problem (HNP). The HNP can be solved efficiently using lattice reduction algorithms — specifically the LLL or BKZ algorithms.
The seminal research on this attack class was published in 2019 by Breitner and Heninger in "Biased Nonce Sense: Lattice Attacks Against Weak ECDSA Signatures in Cryptocurrencies." That paper demonstrated private key recovery from biased ECDSA signatures across Bitcoin, Ethereum, Ripple, SSH, and HTTPS systems. The researchers computed hundreds of private keys from publicly available blockchain data.
In Zilliqa's case, with 64 bits of each nonce fixed at zero, an attacker holding approximately five signatures from the same private key can reconstruct that key in seconds on commodity hardware. The mathematics are deterministic: given enough signatures with known nonce bias, key recovery is not probabilistic — it is certain.
The attack requires no interaction with the victim. All necessary data — the signatures themselves — are permanently and publicly recorded on the Zilliqa blockchain. Any address that broadcast five or more native transactions via the Ledger app should be considered compromised, regardless of whether funds have been moved by an attacker.
The Zilliqa incident is specific to a single application's implementation of Schnorr signatures. It does not reflect a weakness in the Schnorr scheme itself. However, it underscores a persistent risk: the gap between a cryptographic scheme's theoretical security and its actual implementation.
Bitcoin's Taproot upgrade, activated in November 2021, introduced Schnorr signatures via BIP-340. The BIP-340 specification mitigates nonce-related risks through deterministic nonce derivation that combines the private key, message, and auxiliary randomness. The specification also applies key-prefixing — hashing the public key's x-coordinate into the nonce generation — to prevent related-key attacks. Multi-signature protocols built atop BIP-340, including MuSig2 and FROST, handle nonce coordination with additional protocol-level safeguards.
The critical distinction: BIP-340 was designed with awareness of nonce-bias attacks. The Zilliqa Ledger app was not. The error was a buffer offset mistake — not a protocol design failure — but the consequences are cryptographically identical to a protocol-level flaw.
ECDSA implementations face the same class of risk. Deterministic nonce generation (RFC 6979) was introduced specifically to eliminate reliance on random number generators. Applications that bypass RFC 6979 or implement it incorrectly remain vulnerable. The 2019 Breitner-Heninger research found that "hundreds" of Bitcoin and Ethereum private keys could be derived from signatures already recorded on public blockchains.
Ledger has sold over 7 million hardware wallet units. The company's secure element — the tamper-resistant chip that stores private keys — has never been directly compromised in a confirmed attack. However, the ecosystem surrounding Ledger devices has faced repeated security incidents across a different attack surface: software, supply chains, and data systems.
Key incidents include:
The Zilliqa incident adds a new category to this list: a third-party application running on Ledger hardware that contained a cryptographic implementation error. The flaw was in Zilliqa's code, not Ledger's firmware or secure element. But it ran on Ledger's platform, and users trusted their keys to it.
The most consequential aspect of this vulnerability is its irreversibility. The weakened signatures are permanent artifacts of the Zilliqa blockchain. They cannot be deleted, redacted, or overwritten. Any account that produced five or more native Ledger signatures between 2019 and July 2026 is permanently exposed, regardless of whether a corrected app version is installed.
A corrected build of the Zilliqa Ledger app has been prepared and coordinated with Ledger. It restores full-width nonce generation and prevents future weakened signatures. But for already-exposed keys, the only remediation is key retirement: generating a new key pair on unaffected software and transferring all assets to the new address.
Zilliqa has advised affected users to stop using the compromised Ledger app, await official migration instructions, and move funds to fresh addresses generated through unaffected tools. The network's suspension of native transactions provides a temporary circuit breaker, but it also locks affected users out of their own funds until the suspension is lifted.
The Zilliqa Ledger incident is a case study in how a single off-by-eight-bytes error in a cryptographic routine can compromise an entire class of keys irreversibly. The vulnerability was not sophisticated. The exploitation was. Once weakened signatures exist on a public blockchain, key recovery becomes a mathematical exercise, not a hacking challenge.
For the broader industry, the lesson is structural. Cryptographic signature implementations — whether Schnorr or ECDSA — require nonce generation that is either fully deterministic or provably uniform. Buffer handling errors, truncated entropy, and non-standard random number generation remain live risks in any application that signs transactions, regardless of whether the underlying hardware is secure.
Zilliqa's market position limits the dollar impact of this specific incident. But the attack class is chain-agnostic. Any application on any blockchain that produces signatures with biased nonces exposes the same mathematical vulnerability. The 2019 Breitner-Heninger research demonstrated this across Bitcoin, Ethereum, and Ripple. Seven years later, the same class of error persists in production code.