Skip to main content
Sign in

Audit log

Every state-changing event for Zilliqa Exchange Partner Cold Wallet Hack (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-02 12:27:42Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    5eoonzd7CJNS…MUnVr8Josha256 → base58
    verifying row…
    canonical bytes (21277 B) ▸
    {"actor":"system:backfill","investigation_id":"98749b11-466d-49ba-967e-094583968ae7","kind":"publish","page_slug":"zilliqa-exchange-partner-cold-wallet-hack-july-2026","published_at":"2026-08-02T12:27:42.492Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Zilliqa Exchange Partner Cold Wallet Hack (July 2026)","sections":[{"content":"On July 20, 2026, the Zilliqa blockchain development team publicly disclosed that ZIL tokens had been stolen from a cold wallet controlled by an unnamed centralized exchange partner. Zilliqa issued an emergency request to all centralized exchanges (CEXs) to temporarily suspend ZIL deposits and withdrawals as a protective measure. The identity of the affected exchange partner was not publicly disclosed by Zilliqa. Coinone halted ZIL services starting at 19:05 KST on July 20, and KuCoin closed ZIL deposits and withdrawals the same day. Bitget also suspended Zilliqa network deposits and withdrawals, citing wallet maintenance. Zilliqa CEO Alexander Zahnd stated that investigations were ongoing and urged users to follow official channels only.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Zilliqa Reports Security Breach: ZIL Tokens Stolen from Exchange Partner's Cold Wallet","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/zilliqa-reports-security-breach-zil-tokens-stolen-from-exchange-partners-cold-wallet/"},{"credibility":2,"name":"Zilliqa reports ZIL theft from partner cold wallet — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/zilliqa-reports-theft-partner-cold-wallet/"},{"credibility":2,"name":"Zilliqa Halts ZIL Transfers After Exchange Cold Wallet Theft — crypto.news","type":"news_article","url":"https://crypto.news/zilliqa-halts-zil-transfers-after-exchange-cold-wallet-theft/"},{"credibility":2,"name":"Zilliqa: Security Incident at CEX Partner, ZIL Stolen from Cold Wallet — KuCoin","type":"official","url":"https://www.kucoin.com/news/flash/zilliqa-security-incident-at-cex-partner-zil-stolen-from-cold-wallet"},{"credibility":2,"name":"Zilliqa Blockchain Dev Team Alerts Ecosystem To Security Breach — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/07/292919-zilliqa-blockchain-dev-team-alerts-ecosystem-to-security-breach-at-exchange-partners-offline-cold-storage-wallet/"}]},{"content":"On July 21–22, 2026, Zilliqa's investigation isolated the root cause not in exchange-side operational failures but in a cryptographic flaw within the Zilliqa Ledger hardware wallet application. The flaw existed in the Schnorr signature nonce generation routine. The application correctly generated 40 bytes of randomness but copied the wrong 32 bytes into the nonce buffer, retaining eight zero-padding bytes from the reduction process and discarding eight bytes of actual entropy. This caused the most significant 64 bits of each ephemeral nonce to be fixed at zero, drastically weakening the randomness protecting each signature. Using lattice-reduction techniques executable on commodity hardware within seconds, an attacker could reconstruct a wallet's private key after observing approximately five or more native Zilliqa transactions signed by that account. On-chain signatures are immutable; a patched application cannot retroactively protect already-exposed keys. The flaw affected every released version of the Ledger Zilliqa application from its 2019 launch through 2026. Only native (non-EVM) Zilliqa transactions were affected; EVM-compatible transactions and software SDK implementations (zilliqa-js, gozilliqa-sdk, pyzil) remained unaffected.","heading":"Root Cause: Ledger Hardware Wallet Application Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"Zilliqa Reveals Five-Year Ledger Wallet Vulnerability Exposing Private Key — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/zilliqa-reveals-five-year-ledger-wallet-vulnerability-exposing-private-key/"},{"credibility":2,"name":"Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers — crypto.news","type":"news_article","url":"https://crypto.news/zilliqa-ledger-app-flaw-exposes-private-keys-halts-zil-transfers/"},{"credibility":1,"name":"Zilliqa Ledger Security Incident Status — Official Zilliqa Page","type":"official","url":"https://www.zilliqa.com/ledger-incident/"},{"credibility":2,"name":"Incident Report: Ledger Incident Forces Full Freeze on Zilliqa Legacy Transfers — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/incident-report-ledger-incident-forces-full-freeze-on-zilliqa-legacy-transfers-following-critical-app-flaw/"},{"credibility":2,"name":"Zilliqa Halts Native Transactions After Ledger App Flaw Exposes Private Keys — NFT Plazas","type":"news_article","url":"https://nftplazas.com/zilliqa-halts-native-txs-ledger-flaw/"}]},{"content":"According to Zilliqa's official incident status page, approximately 683,130,969.66 ZIL was stolen. At market prices around the time of the incident ($0.0024–$0.0026 per ZIL), this represents an estimated loss of roughly $1.6–1.8 million USD, though the exact dollar value fluctuated with ZIL's price during the period. Zilliqa did not immediately disclose the precise stolen quantity in its initial public communications on July 20; the figure emerged in subsequent disclosures and the official status page published July 24, 2026. The affected party was a single unnamed exchange partner whose cold wallet used the vulnerable Ledger application for native ZIL signing. Accounts that broadcast approximately five or more native transactions using the Zilliqa Ledger app are considered by Zilliqa to be potentially compromised. KuCoin reportedly assisted in confirming ongoing exploitation and tracing the incident during the investigation.","heading":"Stolen Funds and Scope of Loss","severity":"critical","sources":[{"credibility":1,"name":"Zilliqa Ledger Security Incident Status — Official Zilliqa Page","type":"official","url":"https://www.zilliqa.com/ledger-incident/"},{"credibility":2,"name":"Zilliqa Reports Security Breach — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/zilliqa-reports-theft-partner-cold-wallet/"},{"credibility":2,"name":"Zilliqa Ledger Flaw Exposed Keys for 7 Years, Upbit Puts ZIL on Delisting Watch — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/70a2e119-42ff-4596-8847-c3de4ada6d62"}]},{"content":"Following the July 20, 2026 announcement, ZIL immediately declined approximately 15% before partially recovering. The token hit an all-time low of $0.002441 during the incident period. By July 22, ZIL traded at approximately $0.0024, representing a 17% decline over the prior seven days. Trading volume surged approximately 417% to around $20.78 million in the 24 hours after the disclosure, consistent with panic selling and opportunistic trading. ZIL was already trading approximately 99% below its May 2021 all-time high of approximately $0.2563, reflecting a prolonged bear market context preceding the incident.","heading":"Market Impact","severity":"high","sources":[{"credibility":2,"name":"Zilliqa reports ZIL theft from partner cold wallet — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/zilliqa-reports-theft-partner-cold-wallet/"},{"credibility":2,"name":"Zilliqa Incident Report — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/incident-report-ledger-incident-forces-full-freeze-on-zilliqa-legacy-transfers-following-critical-app-flaw/"},{"credibility":2,"name":"Zilliqa Price Drops 6% as Devs Ask Exchanges to Freeze Transfers — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/crimes-and-fraud-news/zilliqa-price-drops-devs-ask-all-exchanges-freeze-transfers/"}]},{"content":"Multiple centralized exchanges responded to Zilliqa's emergency request by suspending ZIL deposits and withdrawals. Coinone halted services at 19:05 KST on July 20. KuCoin suspended deposits and withdrawals on July 20. Bitget suspended Zilliqa network services citing wallet maintenance. South Korean exchange Upbit took a more consequential step on July 22, 2026, designating ZIL as a cautionary asset across both its KRW and BTC markets, suspending deposits and withdrawals while maintaining spot trading temporarily. Upbit warned that trading support could be terminated entirely if the vulnerability and its fallout were not adequately addressed within a review window running through the third week of August 2026. As of the date of this report, ZIL has not been officially delisted from Upbit, but the cautionary designation represents a material delisting risk.","heading":"Exchange Responses and Delisting Risk","severity":"high","sources":[{"credibility":2,"name":"Upbit Puts Altcoin at Risk of Delisting Following Critical Ledger Flaw — BeInCrypto","type":"news_article","url":"https://beincrypto.com/upbit-zilliqa-delisting-watch-ledger-flaw/"},{"credibility":2,"name":"Zilliqa Ledger Flaw Exposed Keys for 7 Years, Upbit Puts ZIL on Delisting Watch — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/70a2e119-42ff-4596-8847-c3de4ada6d62"},{"credibility":2,"name":"Zilliqa's Seven-Year Key Leak Puts Its Upbit Listing at Risk — Coindoo","type":"news_article","url":"https://coindoo.com/zilliqa-key-leak-upbit-listing-risk/"},{"credibility":2,"name":"Zilliqa ZIL Faces Delisting Risk on Upbit After Critical Wallet Flaw — U.Today","type":"news_article","url":"https://u.today/zilliqa-zil-faces-delisting-risk-on-upbit-after-critical-wallet-flaw-emerges"},{"credibility":2,"name":"Zilliqa Ledger App Flaw Exposes Private Keys; Upbit Flags ZIL As Cautionary Asset — Blockchain Reporter","type":"news_article","url":"https://blockchainreporter.net/zilliqa-ledger-app-flaw-exposes-private-keys-upbit-flags-zil-as-cautionary-asset/"}]},{"content":"Zilliqa suspended all native (non-EVM) ZIL transactions on July 21, 2026 as a protective measure. The project coordinated with Ledger to develop a corrected version of the Zilliqa Ledger application that restores full-width nonce generation. However, Zilliqa explicitly acknowledged that installing the patched application cannot protect private keys already exposed through historical on-chain signatures, because those signatures remain permanently recorded on the blockchain. Affected private keys must be considered permanently compromised and must be retired. On July 24, 2026, Zilliqa published an official incident status page. On July 31, 2026, Zilliqa announced a recovery and transition plan: the Zilliqa EVM environment would become the sole production network, with the legacy ZIL1 chain retired. All legacy wallet holders were to be provided with official migration tools. The method for verifying ownership claims for the recovery program was still being designed as of the plan's announcement, with Zilliqa stating an aim to collect as little personal data as possible. Zilliqa indicated it is pursuing fund recovery through exchanges, law enforcement, and blockchain analytics providers.","heading":"Remediation and Recovery Plan","severity":"high","sources":[{"credibility":1,"name":"Zilliqa Ledger Security Incident Status — Official Zilliqa Page","type":"official","url":"https://www.zilliqa.com/ledger-incident/"},{"credibility":2,"name":"Zilliqa Reveals Five-Year Ledger Wallet Vulnerability — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/zilliqa-reveals-five-year-ledger-wallet-vulnerability-exposing-private-key/"},{"credibility":2,"name":"Zilliqa Ledger app flaw exposes private keys — crypto.news","type":"news_article","url":"https://crypto.news/zilliqa-ledger-app-flaw-exposes-private-keys-halts-zil-transfers/"},{"credibility":2,"name":"Zilliqa Suspends Native Transactions After Ledger App Flaw — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/zilliqa-suspends-native-transactions-after-ledger-app-flaw-exposes-private-keys/"}]},{"content":"As of the publication of this report, several material facts remain undisclosed by Zilliqa: the identity of the centralized exchange partner whose cold wallet was the primary theft vehicle; the precise attack vector used to exploit the Ledger flaw against that specific wallet; the current whereabouts of the stolen approximately 683.1 million ZIL; and the specific methodology for the user recovery program. The permanence of the Ledger application flaw — affecting all native ZIL accounts that signed five or more transactions with a Ledger device across any version from 2019 to 2026 — means that the full population of compromised accounts may extend well beyond the directly reported theft. Users who transacted natively via Ledger devices during this period and have not yet migrated their assets face ongoing risk. The recovery program's design remained incomplete as of July 31, 2026, leaving affected holders without a finalized remediation path.","heading":"Undisclosed Information and Ongoing Risks","severity":"high","sources":[{"credibility":1,"name":"Zilliqa Ledger Security Incident Status — Official Zilliqa Page","type":"official","url":"https://www.zilliqa.com/ledger-incident/"},{"credibility":2,"name":"Zilliqa Halts ZIL Transfers After Exchange Cold Wallet Theft — crypto.news","type":"news_article","url":"https://crypto.news/zilliqa-halts-zil-transfers-after-exchange-cold-wallet-theft/"},{"credibility":2,"name":"Zilliqa Reports Security Breach — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/zilliqa-reports-theft-partner-cold-wallet/"}]}],"sources_used":[{"credibility":1,"name":"Zilliqa Ledger Security Incident Status — Official Zilliqa Page","type":"official","url":"https://www.zilliqa.com/ledger-incident/"},{"credibility":2,"name":"Zilliqa Reports Security Breach: ZIL Tokens Stolen from Exchange Partner's Cold Wallet — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/zilliqa-reports-security-breach-zil-tokens-stolen-from-exchange-partners-cold-wallet/"},{"credibility":2,"name":"Zilliqa Reveals Five-Year Ledger Wallet Vulnerability Exposing Private Key — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/zilliqa-reveals-five-year-ledger-wallet-vulnerability-exposing-private-key/"},{"credibility":2,"name":"Zilliqa reports ZIL theft from partner cold wallet — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/zilliqa-reports-theft-partner-cold-wallet/"},{"credibility":2,"name":"Zilliqa Halts ZIL Transfers After Exchange Cold Wallet Theft — crypto.news","type":"news_article","url":"https://crypto.news/zilliqa-halts-zil-transfers-after-exchange-cold-wallet-theft/"},{"credibility":2,"name":"Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers — crypto.news","type":"news_article","url":"https://crypto.news/zilliqa-ledger-app-flaw-exposes-private-keys-halts-zil-transfers/"},{"credibility":2,"name":"Zilliqa Blockchain Dev Team Alerts Ecosystem To Security Breach — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/07/292919-zilliqa-blockchain-dev-team-alerts-ecosystem-to-security-breach-at-exchange-partners-offline-cold-storage-wallet/"},{"credibility":2,"name":"Zilliqa: Security Incident at CEX Partner, ZIL Stolen from Cold Wallet — KuCoin","type":"official","url":"https://www.kucoin.com/news/flash/zilliqa-security-incident-at-cex-partner-zil-stolen-from-cold-wallet"},{"credibility":2,"name":"Upbit Puts Altcoin at Risk of Delisting Following Critical Ledger Flaw — BeInCrypto","type":"news_article","url":"https://beincrypto.com/upbit-zilliqa-delisting-watch-ledger-flaw/"},{"credibility":2,"name":"Zilliqa Ledger Flaw Exposed Keys for 7 Years, Upbit Puts ZIL on Delisting Watch — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/70a2e119-42ff-4596-8847-c3de4ada6d62"},{"credibility":2,"name":"Zilliqa Ledger App Flaw Exposes Private Keys; Upbit Flags ZIL As Cautionary Asset — Blockchain Reporter","type":"news_article","url":"https://blockchainreporter.net/zilliqa-ledger-app-flaw-exposes-private-keys-upbit-flags-zil-as-cautionary-asset/"},{"credibility":2,"name":"Zilliqa ZIL Faces Delisting Risk on Upbit After Critical Wallet Flaw — U.Today","type":"news_article","url":"https://u.today/zilliqa-zil-faces-delisting-risk-on-upbit-after-critical-wallet-flaw-emerges"},{"credibility":2,"name":"Zilliqa's Seven-Year Key Leak Puts Its Upbit Listing at Risk — Coindoo","type":"news_article","url":"https://coindoo.com/zilliqa-key-leak-upbit-listing-risk/"},{"credibility":2,"name":"Zilliqa Suspends Native Transactions After Ledger App Flaw — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/zilliqa-suspends-native-transactions-after-ledger-app-flaw-exposes-private-keys/"},{"credibility":2,"name":"Zilliqa Halts Native Transactions After Ledger App Flaw — NFT Plazas","type":"news_article","url":"https://nftplazas.com/zilliqa-halts-native-txs-ledger-flaw/"},{"credibility":2,"name":"Zilliqa Incident Report: Ledger Incident Forces Full Freeze — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/incident-report-ledger-incident-forces-full-freeze-on-zilliqa-legacy-transfers-following-critical-app-flaw/"},{"credibility":2,"name":"Zilliqa Price Drops 6% as Devs Ask Exchanges to Freeze Transfers — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/crimes-and-fraud-news/zilliqa-price-drops-devs-ask-all-exchanges-freeze-transfers/"}],"summary":"On July 20, 2026, Zilliqa confirmed that ZIL tokens were stolen from a cold wallet held by an unnamed centralized exchange partner, triggering an emergency suspension of ZIL deposits and withdrawals across multiple exchanges. Subsequent investigation revealed the root cause to be a cryptographic flaw in the Zilliqa Ledger hardware wallet application present across all versions since 2019, which allowed attackers to reconstruct private keys from as few as five on-chain native signatures. Approximately 683,130,969.66 ZIL was reported stolen; Zilliqa suspended native legacy transactions entirely and announced plans to migrate all users to the Zilliqa EVM environment.","timeline":[{"date":"2019-01-01","event":"Zilliqa Ledger hardware wallet application released, containing a cryptographic flaw in Schnorr signature nonce generation that would persist undetected for over six years across all subsequent versions.","source":"CryptoTimes / Zilliqa Official","source_url":"https://www.cryptotimes.io/2026/07/22/zilliqa-reveals-five-year-ledger-wallet-vulnerability-exposing-private-key/"},{"date":"2026-07-19","event":"Suspicious on-chain activity consistent with active exploitation of the Ledger application flaw detected.","source":"crypto.news","source_url":"https://crypto.news/zilliqa-ledger-app-flaw-exposes-private-keys-halts-zil-transfers/"},{"date":"2026-07-20","event":"Zilliqa publicly confirmed ZIL tokens stolen from an unnamed exchange partner's cold wallet and issued an emergency request to all CEXs to suspend ZIL deposits and withdrawals. Coinone halted services at 19:05 KST; KuCoin and Bitget also suspended ZIL services. ZIL hit an all-time low of $0.002441 and declined approximately 15% before partial recovery.","source":"CryptoTimes / Cryptopolitan / KuCoin","source_url":"https://www.cryptotimes.io/2026/07/20/zilliqa-reports-security-breach-zil-tokens-stolen-from-exchange-partners-cold-wallet/"},{"date":"2026-07-21","event":"Zilliqa isolated the root cause as a cryptographic flaw in the Zilliqa Ledger application rather than exchange operational failure. Zilliqa suspended all native (non-EVM) ZIL transactions as a protective measure.","source":"crypto.news / CryptoTimes","source_url":"https://crypto.news/zilliqa-ledger-app-flaw-exposes-private-keys-halts-zil-transfers/"},{"date":"2026-07-22","event":"Zilliqa publicly disclosed the Ledger application flaw — a nonce generation bug causing Schnorr signature weaknesses exploitable after approximately five native transactions. Upbit designated ZIL as a cautionary asset across KRW and BTC markets, suspended deposits and withdrawals, and warned of possible delisting pending an August review.","source":"CryptoTimes / BeInCrypto / BigGo Finance","source_url":"https://www.cryptotimes.io/2026/07/22/zilliqa-reveals-five-year-ledger-wallet-vulnerability-exposing-private-key/"},{"date":"2026-07-24","event":"Zilliqa published an official incident status page at zilliqa.com/ledger-incident/ disclosing a stolen amount of approximately 683,130,969.66 ZIL and providing guidance on affected users and recommended actions.","source":"Zilliqa Official","source_url":"https://www.zilliqa.com/ledger-incident/"},{"date":"2026-07-31","event":"Zilliqa announced a recovery and transition plan: the Zilliqa EVM environment to become the sole production network, legacy ZIL1 chain to be retired, and migration tools to be provided to all legacy wallet holders. Recovery program ownership-verification methodology still being designed.","source":"Zilliqa Official","source_url":"https://www.zilliqa.com/ledger-incident/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision e3c3dcc8-4e9f-40c6-97ed-e8c604adcf36
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.