- Nothing can moveEvery legacy transaction is paused, so funds cannot leave any wallet while the pause is in place, including an attacker’s.
- Paused is not affectedEveryone on the legacy side is paused, even people who never touched a Ledger. Most of them are not affected at all.
- There is a way forwardEveryone on the legacy side will be invited to migrate to Zilliqa EVM, and a recovery route is being built for holders of affected accounts. The plan.
Updates
This page is the record for this incident. Every update is logged here, newest first, with the date it was published and what changed; if it is not written down here, it did not come from us.
- 31 July 2026, 10:00 UTCLatest
Recovery and transition plan published
The way forward has been set out: the legacy side is being retired, Zilliqa EVM becomes the only production side, and every legacy wallet holder will be invited to migrate, whether or not they were affected by this incident.
What changed
- Added "The plan from here", the nine-point recovery and transition plan, to this page.
- Confirmed that recovery now runs through a universal migration to Zilliqa EVM, rather than reopening the legacy side.
- No change to the immediate situation: legacy transactions remain paused, the address checker is still being built, and there is nothing you need to do right now.
- 24 July 2026, 16:00 UTC
This status page went live
The incident, who it reaches and who it does not, and the work under way were published in one place, so nobody has to piece the position together from social posts.
What changed
- Published what happened, who is affected and who is not, and what is being done.
- Added the guided self-check, which works out where you stand from what you did rather than from your address.
- Added a way to report a wallet you believe was affected, and the list of accounts that speak for Zilliqa about this incident.
One important distinction
One distinction governs every section below.
This incident affects only the legacy side. Throughout this page, “legacy” means the older, non-EVM Zilliqa. Zilliqa EVM is not affected.
Am I affected?
There is no live checker yet. Answer a question or two and this works out where you stand from what you did, not from your address.
1Have you ever used the Zilliqa Ledger app on a Ledger device to sign a transaction of any kind, sending ZIL, moving ZRC-2 tokens or NFTs, or staking?
Either way, no legacy funds can move while transactions are paused, including affected wallets. There is no live address checker yet; when it is ready it will appear here.
What happened
A security flaw was found in the Zilliqa Ledger application, the app built to sign transactions on the legacy, non-EVM side described above. Because of this flaw, every transaction signed through that app quietly gave away a small piece of information about the wallet’s private key. No single transaction revealed enough to matter, but once a wallet had signed several of them, someone who collected those transactions, which are public on the blockchain, could piece the key together and take the wallet’s funds.
That is why some wallets were emptied without their owners doing anything wrong: nobody was tricked, no device was hacked, and no recovery phrase was stolen. The information leaked through the transactions themselves.
What decides whether a transaction is affected is how it was signed, not when. Only signatures produced by the Zilliqa Ledger app leaked information: a legacy transaction signed another way, for example through the software SDKs, is not affected, and neither is any Zilliqa EVM activity. The flaw is in that one app; the Zilliqa network itself processed every transaction as designed.
Who is affected and who is not
You are not affected if
- you have never used a Ledger device with Zilliqa;
- you used a Ledger, but never with the Zilliqa Ledger application;
- you only ever made EVM transactions;
- you signed only through the software SDKs, zilliqa-js, gozilliqa-sdk and pyzil generate signatures correctly and are not affected; or
- you stake through the official Zilliqa staking portal (stake.zilliqa.com).
You may be affected if
- you used the Zilliqa Ledger application to sign transactions, of any kind, not only sending ZIL;
- that includes sending native ZIL, moving ZRC-2 tokens (ordinary and non-fungible), and staking or unstaking.
When an account is at risk
Every version of the Zilliqa Ledger application is affected, so this does not depend on which version you used. The risk applies to accounts that signed at least four such transactions, that is around the point where the private key can be reconstructed from the public signatures.
An address checker is coming
We are building a checker that will tell you whether a particular address is affected, worked out from the address alone. It is not ready yet. When it is, it will appear on this page, so you can confirm your own situation here rather than through support.
What is not at risk
Your recovery phrase, the words you wrote down when you set up your Ledger, was not exposed by this flaw. Because of that, the only thing that can be at risk is the key to the individual legacy Zilliqa account, rebuilt from its own public signatures. Your Ledger as a whole is not compromised, and funds you hold on other blockchains on the same device, Ethereum and ERC-20 tokens, Solana, anything else, are not at risk. The flaw reaches one signing path and no further.
What if my ZIL is staked?
If your ZIL is staked and earning on Zilliqa EVM, the EVM side of Zilliqa, it is safe: that side is not affected.
If your ZIL is parked in a legacy staking portal or contract, it is paused along with everything else on the legacy side, and it will need the recovery path once that is ready.
Reporting a wallet you believe was affected
If you believe a wallet was affected, you can report it to us. Reporting opens a prefilled email in your own mail app, with our address already written in. The page itself stores nothing and sends nothing on your behalf. It asks for one thing, the address, and nothing else.
Reporting an address is not a claim for compensation, and we cannot promise an individual reply to every report. What it does is help us build a fuller picture of which accounts were touched.
Enter a wallet address before reporting.
Opens your email app with the details prefilled. Your address is not sent to any server.
enquiry@zilliqa.comWe will never DM you after a report, and we will never ask for your recovery phrase.
Do not trust DMs
Incidents like this bring out impersonators offering to “help” you recover your funds. Please be careful.
The Zilliqa team will never contact you first, and will never ask for your seed phrase, private key or recovery phrase, for any reason, ever.
Treat any recovery tool, form or link sent to you privately as hostile, even if it looks official or seems to come from a moderator. Block it, and report it.
The only tools we will ever ask you to use are the ones announced on the official accounts at the end of this page.
What is being done
- Legacy transactions are paused. This stops any further movement. On its own it does not protect a key that is already exposed, which is why the steps below matter.
- The cause has been found and confirmed. A corrected build is being prepared in coordination with Ledger; it protects new accounts going forward, and it does not undo exposure on accounts that have already signed. Those keys will need to be retired.
- Affected wallets are being identified from public blockchain data. This is the same work that will power the address checker.
- A recovery path is being built. The aim is to let people who hold affected accounts move recoverable funds to a fresh address by proving they own the account without ever revealing their seed phrase, a zero-knowledge approach.
- We are not doing this alone. We are coordinating with exchanges and the relevant authorities to trace the funds and the person responsible.
None of these items carries a date, deliberately. We would rather do each one properly than name a day we cannot keep.
The plan from here
The steps above are the immediate response. This is the direction beyond it, published on 31 July 2026, 10:00 UTC.
Recovery runs through migration, not reopening
Rather than reopening the legacy side, the transition to Zilliqa EVM that was already under way will be completed. Zilliqa EVM becomes the only production side, and every legacy wallet holder will be invited to migrate to it, affected or not. Migrating everyone, rather than only the wallets this incident touched, removes the uncertainty about who stands where and gives everybody the same secure starting point.
Complete the move to Zilliqa EVM
The legacy environment was designed for a different security landscape, and keeping it running alongside Zilliqa EVM costs effort that the network’s future needs. The incident brings forward a transition that was already under way; Zilliqa EVM becomes the sole production side.
Open migration to every legacy wallet
Every legacy wallet holder will be invited to migrate to Zilliqa EVM with an official migration tool, whether or not they were touched by this incident. Migrating everyone removes the guesswork and gives the whole ecosystem the same secure starting point.
Migrate the ecosystem, not just wallets
Exchanges, wallet providers, custodians and infrastructure partners will be supported through the move of deposits, withdrawals and integrations, with engineering help throughout, so the transition is coordinated rather than piecemeal.
Strengthen Zilliqa EVM
The validator set, network governance and operational infrastructure will be reviewed and strengthened as part of the transition; legacy components are retired rather than carried forward.
Build a fair recovery framework
Affected holders should have a clear, practical route into a recovery programme. The way ownership is verified is still being designed, with the aim of collecting as little personal data as possible while still giving confidence that a claim is genuine. At the current stage the total amount stolen is estimated at ZIL 683,130,969.66.
Update the tokenomics framework
An updated tokenomics framework restores balances held on the retired side, keeps validator incentives uninterrupted, and sustains the network through the transition.
Keep pursuing the stolen assets
Work continues with law enforcement, exchanges, blockchain analytics providers and ecosystem partners to recover what can be recovered. Legal action will stay targeted and proportionate, weighed against what it can realistically achieve.
Keep communicating in the open
The community, exchanges and partners will get regular updates through the transition, covering not only what is being done but why. This page is where each of those updates is written down.
Hold to the long-term strategy
The incident does not change the direction of the protocol; it makes the case for executing it more decisively. With the legacy side retired, development refocuses on Zilliqa EVM and on the institutional infrastructure the protocol was already being built toward.
One thing worth being plain about. None of this carries a date yet, for the same reason nothing above does: we would rather do each piece properly than name a day we cannot keep. When a step is settled, or when the migration tool is ready, it will appear in Updates with the date and what changed.
What if my funds were lost?
If you have lost funds, we understand what that means, and we are sorry you are going through it.
We are working with exchanges and the relevant authorities to trace the funds and the person responsible, and to work out the best way forward for everyone affected. If there is anything to share on this, it will appear here first.
If you hold ZIL on an exchange
If your ZIL sits on an exchange, it is held by the exchange, not signed by you on a Ledger, so this is a separate situation from everything above. For the status of those funds and what to do next, your point of contact is the exchange’s own support.
Exchanges with questions about the incident can reach us privately at enquiry@zilliqa.com.
Official accounts
These are the only accounts that speak for Zilliqa about this incident. Anything that is not listed here is not us.
- X@zilliqa
- LinkedIncompany/zilliqa
- Instagram@zilliqa_official
- Discorddiscord.gg/zilliqa
- Telegram@zilliqachat
Last updated 31 July 2026, 10:00 UTC. See what changed.