Skip to main content
AVOID.NET

Zilliqa Exchange Partner Cold Wallet Hack (July 2026)

avoid.net/zilliqa-exchange-partner-cold-wallet-hack-july-202612/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3BVGYZ…oW5Z

Summary

On July 20, 2026, Zilliqa confirmed that ZIL tokens were stolen from a cold wallet held by an unnamed centralized exchange partner, triggering an emergency suspension of ZIL deposits and withdrawals across multiple exchanges. Subsequent investigation revealed the root cause to be a cryptographic flaw in the Zilliqa Ledger hardware wallet application present across all versions since 2019, which allowed attackers to reconstruct private keys from as few as five on-chain native signatures. Approximately 683,130,969.66 ZIL was reported stolen; Zilliqa suspended native legacy transactions entirely and announced plans to migrate all users to the Zilliqa EVM environment.

Have evidence about Zilliqa Exchange Partner Cold Wallet Hack (July 2026)?
0
Accepted
2
Under review
0
Rejected / revoked

Community submissions

Timeline(7 events)

2019

Zilliqa Ledger hardware wallet application released, containing a cryptographic flaw in Schnorr signature nonce generation that would persist undetected for over six years across all subsequent versions.

CryptoTimes / Zilliqa Official

19 July 2026

Suspicious on-chain activity consistent with active exploitation of the Ledger application flaw detected.

crypto.news

20 July 2026

Zilliqa publicly confirmed ZIL tokens stolen from an unnamed exchange partner's cold wallet and issued an emergency request to all CEXs to suspend ZIL deposits and withdrawals. Coinone halted services at 19:05 KST; KuCoin and Bitget also suspended ZIL services. ZIL hit an all-time low of $0.002441 and declined approximately 15% before partial recovery.

CryptoTimes / Cryptopolitan / KuCoin

21 July 2026

Zilliqa isolated the root cause as a cryptographic flaw in the Zilliqa Ledger application rather than exchange operational failure. Zilliqa suspended all native (non-EVM) ZIL transactions as a protective measure.

crypto.news / CryptoTimes

22 July 2026

Zilliqa publicly disclosed the Ledger application flaw — a nonce generation bug causing Schnorr signature weaknesses exploitable after approximately five native transactions. Upbit designated ZIL as a cautionary asset across KRW and BTC markets, suspended deposits and withdrawals, and warned of possible delisting pending an August review.

CryptoTimes / BeInCrypto / BigGo Finance

24 July 2026

Zilliqa published an official incident status page at zilliqa.com/ledger-incident/ disclosing a stolen amount of approximately 683,130,969.66 ZIL and providing guidance on affected users and recommended actions.

Zilliqa Official

31 July 2026

Zilliqa announced a recovery and transition plan: the Zilliqa EVM environment to become the sole production network, legacy ZIL1 chain to be retired, and migration tools to be provided to all legacy wallet holders. Recovery program ownership-verification methodology still being designed.

Zilliqa Official
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 16 of 17 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0727 claims checked6 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/2/2026, 12:27:33 PM

last updated: 8/26/2026, 12:10:48 PM

4 views

avoid.net — verified advice for a post-truth world