Zilliqa has suspended all native ZIL transactions after discovering a critical bug in the Ledger hardware wallet app that could expose users' private keys. The vulnerability, tied to a weak nonce generation mechanism, has been present in the app since 2019. The blockchain network confirmed the halt on Tuesday, urging users not to send or receive ZIL until further notice.
How the bug works
The flaw resides in the Ledger app's random number generator. A weak nonce—a number used only once in cryptographic transactions—can allow an attacker to reconstruct a user's private key from signed transactions. That means anyone who used the Ledger app to send ZIL over the past five years may have inadvertently leaked their key material. Zilliqa's team said the bug is not in the Zilliqa protocol itself but in the third-party app that interfaces with the hardware wallet.
Why the suspension was necessary
Zilliqa's decision to freeze native transactions was a precautionary measure. The network said it needed to prevent any further exposure while the Ledger team works on a fix. Users who hold ZIL on exchanges or in other wallets not affected by the bug can still trade or transfer tokens through those platforms. But anyone relying on a Ledger device to send ZIL directly is stuck until the patch arrives.
What users should do now
Zilliqa advised users not to attempt any native ZIL transactions from a Ledger wallet. The company also recommended that anyone who has used the Ledger app for ZIL since 2019 consider their private keys potentially compromised. Moving funds to a new wallet with a fresh seed phrase is the safest course of action—but only after the suspension is lifted. The network said it will announce when it's safe to resume transactions.
Ledger has not yet released a timeline for the fix. The company acknowledged the issue and said it is working on an update. For now, ZIL holders are left waiting, unsure when they'll be able to move their tokens again.




