Morning Edition · Saturday, July 25, 2026Published at 1:44 AM EDT · New York
Zilliqa Halts Native Transfers After a Seven-Year Ledger Flaw Lets Attackers Rebuild Private Keys
A biased signing nonce in the Ledger app means about five signatures from one key are enough to rebuild that key using lattice-reduction mathematics within seconds. The network says exploitation began on July 19.

The layer-1 network Zilliqa has suspended native transactions after concluding that roughly five signatures produced by the same private key can be enough to reconstruct that key. The defect is not a smart-contract bug or a stolen seed phrase. It is a cryptographic implementation error inside the Ledger hardware-wallet app that signs Zilliqa's native (non-EVM) transactions.
The root cause is a biased signing nonce. For each signature the app generated 40 bytes of randomness, reduced the value modulo the secp256k1 curve order, then copied the wrong 32-byte window into the nonce. That mistake fixed the highest 64 bits of every nonce at zero, leaving each value below 2^192. Predictable structure in a signing nonce is the standard condition that lets an attacker apply lattice-reduction techniques and recover the underlying key. Zilliqa says every version of the app shipped between 2019 and 2026 carried the flaw, that it observed on-chain activity consistent with active exploitation on July 19, and that it confirmed the cause on July 21.
Speed now determines the outcome. Because a reconstructed key lets an attacker submit a competing transfer that executes before any ordinary rescue transaction, Zilliqa is building a migration path rather than telling users to simply move funds. The flaw was confined to the native signing path, and the exchange Upbit placed ZIL on a delisting review.
- If true, who benefits
Framing the defect as a flaw in Ledger's signing app, rather than in Zilliqa's protocol, preserves confidence in the chain and shifts liability to the hardware-wallet vendor.
- The nuance
The technical flaw is independently confirmed (KuCoin reproduced key recovery, Upbit restricted ZIL), but the "active exploitation began July 19" claim rests on Zilliqa's reading of on-chain patterns, with no published tally of funds actually taken.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The exposed asset here is the trust premium of hardware wallets, which holders and custodians pay for on the assumption that a device never leaks key material. A deterministic-nonce failure defeats that assumption without any phishing or malware, and the same class of bug (weak or biased ECDSA nonces) has exposed keys before. The parties most exposed are self-custody users of niche signing paths and the wallet vendors whose firmware certifications are the product they sell.
What to watch
- Whether other chains that rely on the same Ledger native-signing routines audit and disclose similar nonce handling, which would widen the scope of the problem beyond Zilliqa.
- How much ZIL is taken before the migration launches, since a working key-recovery attack that moves faster than the fix would show the transfer halt came too late.
- Whether Ledger issues its own analysis of what went wrong and a firmware patch, which institutional custodians need before trusting the device for other assets.
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · crypto.news · Unchained
Part of a tracked trend
Implementation Bugs, Not Just Exploits, Threaten Custody
Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.
More from this edition
- Aztec Activates Alpha V5 on Ethereum Mainnet, Cutting Private Transaction Proving to About 2.5 Seconds
- CLARITY Act Loses Momentum as Thune Doubts a Pre-Recess Vote and Fidelity Presses the Senate
- Strategy Publishes the Bitcoin Return Below Which Its Debt Coverage Breaks: Minus 11.34 Percent a Year
- European Union Sanctions a Russia-Linked Stablecoin Network That Processed About $120 Billion
- DeFi Loss Streak Continues as Oracle, Governance, and Signature Attacks Drain Tens of Millions in July
- FBI Used a Bitcoin Trail, Google Cookies, and 500 Food Orders to Unmask a Malware Financier
- World Foundation Raises $52.5 Million to Scale Proof-of-Human Verification as Deepfake Fears Grow
- Brazilian Dairy Farmers Tokenize Their Cows to Borrow Around Bank Lending Limits
- Bitcoin ETF Buying Streak Ends With $225 Million in Outflows, Led Almost Entirely by BlackRock
- Robinhood Chain Draws Launchpad Funding as Its Value Secured Jumps Even in a Weak Market
- Kazakhstan Will Fund a National Crypto Reserve With a Cut of Miners' Output