← All Flash News

Zilliqa Reveals Critical Ledger App Flaw That Could Expose Private Keys

Crypto Updates, Latest Updates, Market updates

Zilliqa has disclosed a critical security flaw in its Ledger hardware wallet application that could allow attackers to recover users’ private keys from publicly available transaction signatures after roughly five native blockchain transactions.

According to the project, the vulnerability affects every version of the Ledger app released between 2019 and 2026. Zilliqa said active exploitation of the flaw was detected on July 19, prompting an immediate response to limit further risk.

In response, the network suspended native transactions and advised users whose wallets may have been compromised to permanently retire the affected private keys and migrate their assets to newly generated addresses. The issue is limited to Zilliqa’s native transaction format and does not affect transactions conducted on the network’s EVM-compatible environment.

The disclosure also prompted a response from South Korean cryptocurrency exchange Upbit, which placed ZIL under a trading caution notice in its KRW and BTC markets. The exchange said deposits and withdrawals for the token will remain suspended and warned that trading support could be discontinued if the underlying security issue is not resolved.

The incident underscores the potential impact of wallet software vulnerabilities on blockchain users and exchange operations, with both Zilliqa and Upbit implementing measures to reduce further exposure while remediation efforts continue.

Source: Upbit and Zilliqa