Legacy transactions: pausedUpdated 24 July 2026, 16:00 UTC

Ledger security incident

A signing flaw was found in the Zilliqa Ledger app, so all legacy transactions are paused and nothing can move right now, not yours and not an attacker’s. Being paused does not mean you are affected, and most people who are paused are not.

  • Nothing can moveEvery legacy transaction is paused, so funds cannot leave any wallet while the pause is in place, including an attacker’s.
  • Paused is not affectedEveryone on the legacy side is paused, even people who never touched a Ledger. Most of them are not affected at all.
  • There is a way backA recovery path is being built so holders of affected accounts can move recoverable funds to a fresh address, safely.

One important distinction

One distinction governs every section below.

Legacy ZilliqaThe older, non-EVM side of Zilliqa: its accounts, its transactions, and the Zilliqa Ledger application built for it.
Zilliqa 2 (EVM)The newer, EVM-compatible side of Zilliqa.

This incident affects only the legacy side. Throughout this page, “legacy” means the older, non-EVM Zilliqa. Zilliqa 2 (EVM) is not affected.

Am I affected?

There is no live checker yet. Answer a question or two and this works out where you stand from what you did, not from your address.

1Have you ever used the Zilliqa Ledger app on a Ledger device to sign a transaction of any kind, sending ZIL, moving ZRC-2 tokens or NFTs, or staking?

Either way, no legacy funds can move while transactions are paused, including affected wallets. There is no live address checker yet; when it is ready it will appear here.

What happened

A security flaw was found in the Zilliqa Ledger application, the app built to sign transactions on the legacy, non-EVM side described above. Because of this flaw, every transaction signed through that app quietly gave away a small piece of information about the wallet’s private key. No single transaction revealed enough to matter, but once a wallet had signed several of them, someone who collected those transactions, which are public on the blockchain, could piece the key together and take the wallet’s funds.

That is why some wallets were emptied without their owners doing anything wrong: nobody was tricked, no device was hacked, and no recovery phrase was stolen. The information leaked through the transactions themselves.

What decides whether a transaction is affected is how it was signed, not when. Only signatures produced by the Zilliqa Ledger app leaked information: a legacy transaction signed another way, for example through the software SDKs, is not affected, and neither is any Zilliqa 2 (EVM) activity. The flaw is in that one app; the Zilliqa network itself processed every transaction as designed.

Who is affected and who is not

You are not affected if

  • you have never used a Ledger device with Zilliqa;
  • you used a Ledger, but never with the Zilliqa Ledger application;
  • you only ever made EVM transactions;
  • you signed only through the software SDKs, zilliqa-js, gozilliqa-sdk and pyzil generate signatures correctly and are not affected; or
  • you stake through the official Zilliqa staking portal (stake.zilliqa.com).

You may be affected if

  • you used the Zilliqa Ledger application to sign transactions, of any kind, not only sending ZIL;
  • that includes sending native ZIL, moving ZRC-2 tokens (ordinary and non-fungible), and staking or unstaking.

When an account is at risk

Every version of the Zilliqa Ledger application is affected, so this does not depend on which version you used. The risk applies to accounts that signed at least four such transactions, that is around the point where the private key can be reconstructed from the public signatures.

An address checker is coming

We are building a checker that will tell you whether a particular address is affected, worked out from the address alone. It is not ready yet. When it is, it will appear on this page, so you can confirm your own situation here rather than through support.

What is not at risk

Your recovery phrase, the words you wrote down when you set up your Ledger, was not exposed by this flaw. Because of that, the only thing that can be at risk is the key to the individual legacy Zilliqa account, rebuilt from its own public signatures. Your Ledger as a whole is not compromised, and funds you hold on other blockchains on the same device, Ethereum and ERC-20 tokens, Solana, anything else, are not at risk. The flaw reaches one signing path and no further.

What if my ZIL is staked?

If your ZIL is staked and earning on Zilliqa 2, the EVM side of Zilliqa, it is safe: that side is not affected.

If your ZIL is parked in a legacy staking portal or contract, it is paused along with everything else on the legacy side, and it will need the recovery path once that is ready.

Reporting a wallet you believe was affected

If you believe a wallet was affected, you can report it to us. Reporting opens a prefilled email in your own mail app, with our address already written in. The page itself stores nothing and sends nothing on your behalf. It asks for one thing, the address, and nothing else.

Reporting an address is not a claim for compensation, and we cannot promise an individual reply to every report. What it does is help us build a fuller picture of which accounts were touched.

Opens your email app with the details prefilled. Your address is not sent to any server.

If the button does not open your email app, report it directly:enquiry@zilliqa.com

We will never DM you after a report, and we will never ask for your recovery phrase.

Do not trust DMs

Incidents like this bring out impersonators offering to “help” you recover your funds. Please be careful.

The Zilliqa team will never contact you first, and will never ask for your seed phrase, private key or recovery phrase, for any reason, ever.

Treat any recovery tool, form or link sent to you privately as hostile, even if it looks official or seems to come from a moderator. Block it, and report it.

The only tools we will ever ask you to use are the ones announced on the official accounts at the end of this page.

What is being done

  • Legacy transactions are paused. This stops any further movement. On its own it does not protect a key that is already exposed, which is why the steps below matter.
  • The cause has been found and confirmed. A corrected build is being prepared in coordination with Ledger; it protects new accounts going forward, and it does not undo exposure on accounts that have already signed. Those keys will need to be retired.
  • Affected wallets are being identified from public blockchain data. This is the same work that will power the address checker.
  • A recovery path is being built. The aim is to let people who hold affected accounts move recoverable funds to a fresh address by proving they own the account without ever revealing their seed phrase, a zero-knowledge approach.
  • We are not doing this alone. We are coordinating with exchanges, the relevant authorities, and Ledger to trace the funds and the person responsible.

None of these items carries a date, deliberately. We would rather do each one properly than name a day we cannot keep.

What if my funds were lost?

If you have lost funds, we understand what that means, and we are sorry you are going through it.

We are working with exchanges and the relevant authorities to trace the funds and the person responsible, and to work out the best way forward for everyone affected. If there is anything to share on this, it will appear here first.

If you hold ZIL on an exchange

If your ZIL sits on an exchange, it is held by the exchange, not signed by you on a Ledger, so this is a separate situation from everything above. For the status of those funds and what to do next, your point of contact is the exchange’s own support.

Exchanges with questions about the incident can reach us privately at enquiry@zilliqa.com.

Official accounts

These are the only accounts that speak for Zilliqa about this incident. Anything that is not listed here is not us.

Last updated 24 July 2026, 16:00 UTC.