How an Attacker Recovered Private Keys on Ledger: Zilliqa Attack (2026)

How an Attacker Recovered Private Keys on Ledger: Zilliqa Attack (2026)


On July 19, 2026, you probably heard about a hack on the Zilliqa blockchain. After the initial few days, an official statement from the team was released on July 22, 2026, and the picture is much clearer (and disturbing) than in the first few hours. Essentially, two things happened:

1) A theft of approximately 159 million ZIL (~$420,000) from a cold wallet belonging to a partner exchange;

2) A critical vulnerability was discovered in the Zilliqa Ledger App, which is likely the technical cause behind the theft (or at least the first wave of compromises).

 

VULNERABILITY
From what it appears, this is not a vulnerability in the Zilliqa blockchain or in consensus. This is a bug in the Ledger app for native Zilliqa transactions, introduced with the first release in 2019 and remaining undetected until 2026.

The vulnerability only affects native Zilliqa transactions (Schnorr signatures). The following are not affected:
- Zilliqa EVM.
- Zilliqa-js.
- Gozilliqa-sdk.
- Pyzil.
- All ECDSA/EVM signatures.

ec66498b5062c7c572b901e6aa4fdc78ab8a9d3e7b1bcd1ddfbf1ff50082df2c.jpg

 

LEDGER ZILLIQA BUG
Each Schnorr signature requires a completely unpredictable random number ("nonce"). Ledger should have generated a random 256-bit nonce. Instead, due to an error in copying the memory:

- 8 bytes were always kept the same (zero).
- 64 bits of entropy were lost.

As a result, the nonce was: k < 2^192 instead of k < 2^256. This means that each signature loses some of its randomness. A single signature isn't enough. But after about five signatures, the entire private key can be recovered using a mathematical attack called:

"Hidden Number Problem + Lattice Reduction (LLL/BKZ)" (a technique known for years in cryptography).

3e38f1b109a08638d168d1a22b40e528beecc7dc9098114100f2a0034092b214.jpg

Normally, a software update would be enough to fix the problem. This isn't the case, because the vulnerable signatures are already permanently recorded on the blockchain. Anyone could download the transactions, extract the signatures, and reconstruct the private key. This is why Zilliqa advised Ledger holders to do nothing and wait for instructions. Many users obviously thought:

"If someone could find my private key, just send the ZIL to a new wallet, so I have a different private key."

In reality, this would be dangerous. As soon as native transactions are reactivated: you sign the transaction, the attacker already has your private key and can sign an identical one by paying more fees and front-running your transfer. For this reason, Zilliqa has completely suspended native transactions.

 

COLD WALLET HACKED
Investigations have confirmed that 159 million ZIL, equivalent to approximately $420k (a paltry sum), was stolen. The on-chain data shows:
46 dormant wallets, consolidation, and subsequent split into 30 million ZIL, 30 million ZIL, and 99 million ZIL. Zilliqa immediately requested exchanges to halt deposits and withdrawals to prevent fund laundering. Recently, KuCoin announced it had recovered the private keys and verified that the attacks were in progress. It is therefore plausible that the cold wallet belonged to an operator using Ledger to sign native transactions. However, Zilliqa has not yet publicly confirmed that the cold wallet theft was caused by this vulnerability.
According to Zilliqa, KuCoin identified the issue, managed to reconstruct the private keys, confirmed that the exploits were genuine, and assisted in the remediation. This suggests that the issue was discovered by analyzing suspicious transactions.

 

AFFECTED VERSIONS
All versions of the Ledger App related to Zilliqa are therefore affected from 2019 to July 2026. If a user has made ~5 or more native transactions with Ledger, their private key should be considered compromised. It doesn't matter if they update the firmware; the key should be permanently abandoned.
As mentioned, to limit the damage: native transactions are suspended, a new, patched Ledger App is ready, and a coordinated remediation is underway. ZIL lost approximately 10% in a few hours. The token was already near all-time lows (over 99% below its 2021 high), so the news has worsened an already fragile state of trust.

 

Article always updated with all the possibilities of on-chain farming (airdrop)Some Sites To Earn Crypto Bonus (Old & New)  

How do you rate this article?

10


☑️0🆇D̺͈͙͕̿ͧ̑ͣ🅰🆅🅸🅳eͤ
☑️0🆇D̺͈͙͕̿ͧ̑ͣ🅰🆅🅸🅳eͤ Verified Member

I love Bitcoin since 2012. I also love NFT. #BTC #ETH #MLBSorare


Darknet
Darknet

The topics will be 🅒🅡🅨🅟🅣🅞, of course. BTC and Degen crypto since 2012.⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?