Zilliqa disclosed a critical security vulnerability affecting its Ledger application that allows private keys to be reconstructed from public signatures after only five native Zilliqa transactions. The flaw, detailed in a July 22, 2026 tweet from Zilliqa's official account, stems from a nonce-generation issue in Schnorr signature creation for native (non-EVM) Zilliqa transactions. Private keys serve as the foundation of cryptocurrency wallet security, and their compromise could enable unauthorized access to users' digital assets. Following the disclosure, cryptocurrency exchange Upbit designated ZIL as a cautionary asset, signaling heightened monitoring of the token's security environment.
Zilliqa Discloses Ledger App Vulnerability Allowing Private Key Reconstruction
The disclosed vulnerability allows private keys to be reconstructed from public signatures after only five native Zilliqa transactions, creating a significant security risk for users of the affected Ledger application. Security experts generally regard private key protection as one of the most critical aspects of blockchain infrastructure.
On July 22, 2026, Zilliqa's official Twitter account stated: "Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated…"
The flaw affects the Zilliqa Ledger application's implementation of Schnorr signatures specifically for native Zilliqa transactions, not EVM-compatible transactions on the network.
Upbit Designates ZIL as Cautionary Asset
Cryptocurrency exchange Upbit designated ZIL as a cautionary asset following the vulnerability disclosure. The designation reflects heightened concerns surrounding the token's security environment and signals that the exchange is closely monitoring developments related to the incident while encouraging users to exercise additional caution when trading or holding the asset.
Prior Security Incident Adds to Ecosystem Concerns
On July 20, 2026, Zilliqa's official Twitter account disclosed an earlier unrelated security incident: "We have been made aware of a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet. The incident is under active investigation, and we are working with the relevant parties to establish the root cause and full scope."
While the two incidents are unrelated in nature, the latest Ledger application disclosure adds to concerns surrounding the ecosystem's overall security posture. The earlier incident involved theft of ZIL tokens from a partner organization's cold wallet and remains under active investigation.
FAQ
What vulnerability did Zilliqa disclose in its Ledger application?
Zilliqa disclosed a critical vulnerability that allows private keys to be reconstructed from public signatures after only five native Zilliqa transactions. The flaw affects the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions due to a nonce-generation issue in the Ledger application.
How did Upbit respond to the Zilliqa Ledger app vulnerability?
Upbit designated ZIL as a cautionary asset following the vulnerability disclosure. The exchange is closely monitoring developments related to the incident and encouraging users to exercise additional caution when trading or holding the asset.