Zilliqa (ZIL) is teetering on the edge of being removed from two of South Korea’s largest cryptocurrency exchanges after a severe vulnerability was uncovered in its Ledger hardware wallet application. The flaw, disclosed on July 22, 2026, allows attackers to recover private keys from publicly available on-chain signatures after just about five native transactions.
The critical nonce-generation weakness affects all versions of the Zilliqa Ledger app released between 2019 and 2026. Active exploitation was spotted on July 19, prompting Zilliqa to immediately suspend all native ZIL transactions. The team stressed that Ethereum Virtual Machine (EVM) transactions are not impacted, but any account that has sent around five or more native transactions via the Ledger app should be considered compromised—its private key can be reconstructed from existing signature data.
In response, Upbit and Bithumb have both designated ZIL as a “cautionary asset.” They halted deposits and withdrawals and warned that trading support for ZIL in KRW and BTC markets could be permanently terminated if the security issue is not resolved in a timely manner or if adequate investor protection measures are not implemented. Zilliqa’s team says protective steps are already in place and a coordinated remediation plan is being finalized, but the damage to user confidence is already visible.