A hardware wallet vulnerability, which went undetected for seven years, forced Zilliqa to suspend all local transactions after attackers began exploiting the vulnerability on July 19. An undetected bug in the Zilliqa Ledger app allowed private keys to be recovered from public signatures after approximately five on-chain transactions, according to Original report. Every version released between 2019 and 2026 has been affected.
This revelation has already sparked a sharp response from the stock market. South Korea’s Upbit has designated ZIL as a warning asset across KRW and BTC trading pairs, suspended deposits and withdrawals, and warned that trading support could end entirely if the issue is not remedied quickly. The move immediately amplifies the pressure on the Zilliqa development team, which must now contend not only with patching the bug but also with the specter of losing one of its most important exchange listings.
How a flaw harms security
The vulnerability lies at the intersection of hardware wallet design and Zilliqa implementation. A nonce — a single-use number — is supposed to ensure that each transaction signature is unique. When nonsense characters are incorrectly generated, an observer collecting multiple signatures of the same private key can reconstruct the same key. The problem is particularly serious because it does not require malware to be present on the user’s device; The opponent only needs to see publicly broadcast signatures from about five local transfers. The exploitation timeline indicates that active exploitation began before the public consultation was issued, raising the possibility that funds would be taken before the network could respond.
The immediate mitigation taken by Zilliqa was to stop local transactions completely. EVM-based activity on the network is not affected, but for many long-term owners who have used the Ledger app, stopping compromised keys is now essential. This process – creating new wallets and transferring assets – carries its own risks if users are not careful. At the same time, the incident casts a long shadow over confidence in the hardware wallet integrations of lesser-known chains, where security audits may be thinner than those of Ethereum or Bitcoin.
Upbit red flag and delisting threat
Upbit’s asset warning designation is not a complete delisting, but serves as a general warning that the exchange’s risk management team sees a material threat to users’ funds. Korean exchanges have become increasingly aggressive with such flags in the wake of regulatory directives and past incidents, where failure to act quickly has drawn scrutiny. The similarity between this measure and the broader push toward exchange rate accountability is difficult to ignore Regulatory pressures on cryptocurrency infrastructure have intensifiedTrading platforms have little tolerance for assets that cause custody layer risk.
As for ZIL’s liquidity, the suspension of deposits and withdrawals at a major venue like Upbit tightens the exit methods available to Korean traders. While the token remains listed for the time being, the warning creates a binary outcome: either Zilliqa corrects the flaw and satisfies Upbit’s review, or trading is terminated. Meanwhile, market participants are watching whether other exchanges will follow Upbit’s lead, which could exacerbate the token’s liquidity crisis.
What remains unresolved
The extent of the damage is still unclear. Neither Zilliqa nor Upbit disclosed how many private keys were actually compromised during the exploit, nor the total dollar loss. Additionally, the fact that the flaw has been present in every version of the Ledger app for seven years raises questions about the chain’s comprehensive security review process and how many other integrated apps may contain similar, never-before-seen vulnerabilities. Developer trust metrics have already become a benchmark for chain health, and are tracked through efforts such as Weekly developer activity rankingsIncidents like this can quickly erode that trust.
For hardware wallet users, this warning is a reminder that the Ledger does not remove risk, it only changes it. A vulnerability in an application that signs transactions can be just as devastating as a compromised seed phrase. The Zilliqa incident will likely trigger a new round of scrutiny across other chains’ Ledger integrations, particularly those with smaller developer communities where such flaws can persist without warning. Until these audits are complete, the market will have to be mindful of the possibility that similar vulnerabilities are lurking elsewhere.





