Skip to main content
Sign in

Zilliqa Exchange Partner Cold Wallet Hack (July 2026)

avoid.net/zilliqa-exchange-partner-cold-wallet-hack-july-202622/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

On July 20, 2026, Zilliqa confirmed that ZIL tokens were stolen from a cold wallet held by an unnamed centralized exchange partner, triggering an emergency suspension of ZIL deposits and withdrawals across multiple exchanges. Subsequent investigation revealed the root cause to be a cryptographic flaw in the Zilliqa Ledger hardware wallet application present across all versions since 2019, which allowed attackers to reconstruct private keys from as few as five on-chain native signatures. Approximately 683,130,969.66 ZIL was reported stolen; Zilliqa suspended native legacy transactions entirely and announced plans to migrate all users to the Zilliqa EVM environment.

Have evidence about Zilliqa Exchange Partner Cold Wallet Hack (July 2026)?

Timeline(7 events)

2019-01-01

Zilliqa Ledger hardware wallet application released, containing a cryptographic flaw in Schnorr signature nonce generation that would persist undetected for over six years across all subsequent versions.

CryptoTimes / Zilliqa Official

2026-07-19

Suspicious on-chain activity consistent with active exploitation of the Ledger application flaw detected.

crypto.news

2026-07-20

Zilliqa publicly confirmed ZIL tokens stolen from an unnamed exchange partner's cold wallet and issued an emergency request to all CEXs to suspend ZIL deposits and withdrawals. Coinone halted services at 19:05 KST; KuCoin and Bitget also suspended ZIL services. ZIL hit an all-time low of $0.002441 and declined approximately 15% before partial recovery.

CryptoTimes / Cryptopolitan / KuCoin

2026-07-21

Zilliqa isolated the root cause as a cryptographic flaw in the Zilliqa Ledger application rather than exchange operational failure. Zilliqa suspended all native (non-EVM) ZIL transactions as a protective measure.

crypto.news / CryptoTimes

2026-07-22

Zilliqa publicly disclosed the Ledger application flaw — a nonce generation bug causing Schnorr signature weaknesses exploitable after approximately five native transactions. Upbit designated ZIL as a cautionary asset across KRW and BTC markets, suspended deposits and withdrawals, and warned of possible delisting pending an August review.

CryptoTimes / BeInCrypto / BigGo Finance

2026-07-24

Zilliqa published an official incident status page at zilliqa.com/ledger-incident/ disclosing a stolen amount of approximately 683,130,969.66 ZIL and providing guidance on affected users and recommended actions.

Zilliqa Official

2026-07-31

Zilliqa announced a recovery and transition plan: the Zilliqa EVM environment to become the sole production network, legacy ZIL1 chain to be retired, and migration tools to be provided to all legacy wallet holders. Recovery program ownership-verification methodology still being designed.

Zilliqa Official
Provenance & Audit Trail
12 Wayback Archives

Decision Log

  • #1publish⛓ pending8/2/2026, 12:27:42 PM
    hash: 5eoonzd7CJNSiaJyc999SsJ8ALcZqNBcL2EJMUnVr8Jo

12 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/2/2026, 12:27:33 PM

last updated: 8/2/2026, 5:16:07 PM

avoid.net — verified advice for a post-truth world