Crypto news report · source clearly identified
Zilliqa Ledger Bug Leads to Theft of 683 Million ZIL
A flaw in Zilliqa’s legacy Ledger signing application discarded entropy, exposing private keys and enabling the theft of over 683 million ZIL from more than 6,700 accounts.

A post‑mortem released by Zilliqa details a hardware‑wallet bug that exposed private keys for at least 6,772 accounts and resulted in the theft of 683,130,969.66 ZIL across 66 transactions.
Technical cause of the exposure
The legacy Ledger signing application generated 40 random bytes but copied only the wrong 32 bytes into its signing buffer, leaving eight bytes of zero padding and discarding eight bytes of entropy. This forced the high 64 bits of every affected nonce to zero. When four or more biased signatures were produced for the same account, an attacker could reconstruct the private key from public blockchain data in seconds on ordinary hardware.
Scope of the incident
- 6,772 accounts had private keys shown to be exposed; 51 of those were confirmed drained.
- The bulk scan counted accounts with at least five biased signatures; cases with exactly four signatures were not included in the initial count.
- The flaw is limited to Zilliqa’s legacy, non‑EVM signing path. EVM activity, recovery phrases, assets on other blockchains, and software‑wallet signing paths were not affected.
Timeline
- First proven theft dated to March 4.
- KuCoin reported anomalous outgoing transactions from a cold wallet on July 19.
- Last attacker transaction recorded at 09:19:09 UTC on July 20.
- Zilliqa disabled legacy transactions around 12:59 UTC on July 20.
Response and remediation
Zilliqa stated that it authored the original implementation, while the flaw persisted through years of Ledger maintenance. The company plans to migrate all legacy holders to the Zilliqa EVM and retire the legacy signing path, pending a security audit and any required remediation. Asset tracing and coordination with exchanges continue.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- August 24, 2026, 6:10 PM
- Original headline
- Zilliqa points to hardware wallet flaw discarding entropy to expose crypto keys, enabling 683M ZIL theft