Main South Korean cryptocurrency change Upbit has flagged Zilliqa (ZIL) as a cautionary asset following the invention of a important vulnerability in its Ledger utility.
Based on Wu Blockchain, Upbit has positioned ZIL below cautionary asset standing, elevating considerations over the token’s future buying and selling help on the crypto change, with the opportunity of delisting it if the safety difficulty is not resolved.
Earlier as we speak, July 22, Zilliqa disclosed a important nonce-generation flaw in its Ledger app that permits personal keys to be recovered from public signatures after about 5 native transactions.
The problem impacts all variations launched from 2019 to 2026, with lively exploitation noticed on July 19. Native Zilliqa transactions have been suspended, with affected keys set to be retired, whereas EVM transactions are unaffected.
XRP, Cardano (ADA), Stellar (XLM) and Bitcoin (BTC) Worth Evaluation for July 22: Bulls Are Waking Up
Telegram’s Durov Teases Largest Non-Custodial Crypto Pockets Launch
Upbit subsequently designated ZIL as a cautionary asset throughout its KRW and BTC markets. ZIL deposits and withdrawals stay suspended, and buying and selling help could also be terminated if the difficulty will not be resolved.
What occurred?
On July 22, Zilliqa introduced the invention of a nonce-generation vulnerability in its Ledger app in an X publish.
A important vulnerability was recognized within the Zilliqa Ledger utility affecting the era of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can get better the signer’s personal key utilizing solely publicly obtainable on-chain information.
The Zilliqa staff famous that protecting measures are already in place to stop additional loss, and a coordinated remediation plan is being finalized.
The vulnerability impacts personal keys used to signal native Zilliqa transactions with a Ledger gadget, and any account that has broadcast about 5 or extra native transactions signed by way of the Zilliqa Ledger app ought to be thought of compromised. It is because their personal keys might be reconstructed from signatures already recorded on-chain, no matter any subsequent software program replace.
The problem is, nevertheless, confined to the Ledger app’s native signing path, with EVM transactions unaffected.


