Skip to main content
AVOID.NET
Zilliqa Exchange Partner Cold Wallet Hack (July 2026)reviewed 2026-09-07 · 27 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Zilliqa Exchange Partner Cold Wallet Hack (July 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #14[disputed][awaiting moderator]in section: Market Impact
    Following the July 20, 2026 announcement, ZIL immediately declined approximately 15% before partially recovering.
    reviewerZIL immediately declined approximately 15% following the July 20 announcement before partially recoveringNo source consulted, including the two sources cited directly in this section, reports a 15% immediate decline; they report 6% and 1.5% respectively. The 15% figure appears to be an error, possibly a misreading of the unrelated 99%-below-ATH or 17%-over-7-days figures.
    Proposed correction (not yet applied)
    Following the July 20, 2026 announcement, ZIL immediately declined approximately 6% before partially recovering.
  2. #15[disputed][awaiting moderator]in the timeline
    ZIL hit an all-time low of $0.002441 and declined approximately 15% before partial recovery.
    reviewerZIL hit an all-time low of $0.002441 and declined approximately 15% before partial recovery (timeline, July 20)Same underlying error as the Market Impact section's 15% figure; repeats the unsupported number in the timeline.
    Proposed correction (not yet applied)
    ZIL hit an all-time low of $0.002441 and declined approximately 6% before partial recovery.

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #22[unverifiable][awaiting moderator]in section: Remediation and Recovery Plan
    The project coordinated with Ledger to develop a corrected version of the Zilliqa Ledger application that restores full-width nonce generation.
    reviewerZilliqa coordinated with Ledger to develop a corrected version of the Ledger application restoring full-width nonce generationPlausible given the app is Ledger's own hardware wallet software, but no source directly confirms Ledger's specific role as described; could not independently verify this detail.

stale

3 claims

The claim was accurate when written but events since have overtaken it.

  1. #7[stale][awaiting moderator]in the summary
    Subsequent investigation revealed the root cause to be a cryptographic flaw in the Zilliqa Ledger hardware wallet application present across all versions since 2019, which allowed attackers to reconstruct private keys from as few as five on-chain native signatures.
    reviewerAttackers could reconstruct private keys from as few as five on-chain native signatures (summary)Accurately reflected initial (July 22) reporting, but Zilliqa's own later post-mortem revises the true minimum down to four signatures; five was merely the scan threshold used for the population count.
    Proposed correction (not yet applied)
    Subsequent investigation revealed the root cause to be a cryptographic flaw in the Zilliqa Ledger hardware wallet application present across all versions since 2019, which allowed attackers to reconstruct private keys from as few as four on-chain native signatures.
  2. #8[stale][awaiting moderator]in section: Root Cause: Ledger Hardware Wallet Application Vulnerability
    Using lattice-reduction techniques executable on commodity hardware within seconds, an attacker could reconstruct a wallet's private key after observing approximately five or more native Zilliqa transactions signed by that account.
    reviewerAttacker could reconstruct a private key after observing approximately five or more native transactions (root cause section)Same underlying error as the summary claim; superseded by Zilliqa's own post-mortem.
    Proposed correction (not yet applied)
    Using lattice-reduction techniques executable on commodity hardware within seconds, an attacker could reconstruct a wallet's private key after observing approximately four or more native Zilliqa transactions signed by that account.
  3. #26[stale][awaiting moderator]in section: Undisclosed Information and Ongoing Risks
    As of the publication of this report, several material facts remain undisclosed by Zilliqa: the identity of the centralized exchange partner whose cold wallet was the primary theft vehicle; the precise attack vector used to exploit the Ledger flaw against that specific wallet; the current whereabouts of the stolen approximately 683.1 million ZIL; and the specific methodology for the user recovery program.
    reviewerSeveral material facts, including the current whereabouts of the stolen ~683.1 million ZIL, remain undisclosed by ZilliqaAccurate as of the page's July 31, 2026 cutoff, but superseded by Zilliqa's later post-mortem which discloses that at least one liquidation account was identified and frozen.
    Proposed correction (not yet applied)
    As of the publication of this report, several material facts remain undisclosed by Zilliqa: the identity of the centralized exchange partner whose cold wallet was the primary theft vehicle; the precise attack vector used to exploit the Ledger flaw against that specific wallet; the full whereabouts of the stolen approximately 683.1 million ZIL beyond a single exchange account identified and frozen, as disclosed in Zilliqa's subsequent incident post-mortem; and the specific methodology for the user recovery program.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #5[partially supported][awaiting moderator]in section: Incident Overview
    Zilliqa CEO Alexander Zahnd stated that investigations were ongoing and urged users to follow official channels only.
    reviewerZilliqa CEO Alexander Zahnd stated investigations were ongoing and urged users to follow official channels onlyZahnd's identity, role, and general messaging are confirmed, but the specific framing 'urged users to follow official channels only' is a paraphrase not verified verbatim in any source consulted.

confirmed

19 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Incident Overview
    On July 20, 2026, the Zilliqa blockchain development team publicly disclosed that ZIL tokens had been stolen from a cold wallet controlled by an unnamed centralized exchange partner.
    reviewerZilliqa publicly disclosed on July 20, 2026 that ZIL tokens had been stolen from a cold wallet controlled by an unnamed CEX partnerCorroborated by independent secondary reporting; the primary cited CryptoTimes URL returned a bot-verification interstitial when fetched directly but the fact is well corroborated elsewhere.
  2. #2[confirmed][no action needed]in section: Incident Overview
    Zilliqa issued an emergency request to all centralized exchanges (CEXs) to temporarily suspend ZIL deposits and withdrawals as a protective measure.
    reviewerZilliqa issued an emergency request to all CEXs to suspend ZIL deposits/withdrawalsDirectly corroborated.
  3. #3[confirmed][no action needed]in section: Incident Overview
    Coinone halted ZIL services starting at 19:05 KST on July 20, and KuCoin closed ZIL deposits and withdrawals the same day.
    reviewerCoinone halted ZIL services at 19:05 KST on July 20; KuCoin closed ZIL deposits and withdrawals the same dayCore fact confirmed; the precise 19:05 KST timestamp could not be independently re-verified beyond the page's own cited sources but is plausible and uncontradicted.
  4. #4[confirmed][no action needed]in section: Incident Overview
    Bitget also suspended Zilliqa network deposits and withdrawals, citing wallet maintenance.
    reviewerBitget suspended Zilliqa network deposits/withdrawals citing wallet maintenanceDirectly confirmed by Bitget's own notice.
  5. #6[confirmed][no action needed]in section: Root Cause: Ledger Hardware Wallet Application Vulnerability
    The application correctly generated 40 bytes of randomness but copied the wrong 32 bytes into the nonce buffer, retaining eight zero-padding bytes from the reduction process and discarding eight bytes of actual entropy.
    reviewerTechnical root cause: app generated 40 bytes of randomness but copied the wrong 32 bytes into the nonce buffer, retaining 8 zero-padding bytes and discarding 8 bytes of entropyTechnical description matches both the cited news source and the official post-mortem.
  6. #9[confirmed][no action needed]in section: Root Cause: Ledger Hardware Wallet Application Vulnerability
    The flaw affected every released version of the Ledger Zilliqa application from its 2019 launch through 2026. Only native (non-EVM) Zilliqa transactions were affected; EVM-compatible transactions and software SDK implementations (zilliqa-js, gozilliqa-sdk, pyzil) remained unaffected.
    reviewerLedger app flaw affected all versions 2019-2026; only native (non-EVM) transactions affected, SDKs unaffectedConfirmed by the official Zilliqa incident page.
  7. #10[confirmed][no action needed]in section: Stolen Funds and Scope of Loss
    According to Zilliqa's official incident status page, approximately 683,130,969.66 ZIL was stolen.
    reviewerApproximately 683,130,969.66 ZIL was stolen, per Zilliqa's official incident status pageDirectly confirmed on the official status page and multiple secondary sources.
  8. #11[confirmed][no action needed]in section: Stolen Funds and Scope of Loss
    At market prices around the time of the incident ($0.0024–$0.0026 per ZIL), this represents an estimated loss of roughly $1.6–1.8 million USD, though the exact dollar value fluctuated with ZIL's price during the period.
    reviewerAt $0.0024-$0.0026/ZIL, the stolen amount represents roughly $1.6-1.8 million USDArithmetic checks out against the reported ZIL price range for the period.
  9. #12[confirmed][no action needed]in section: Stolen Funds and Scope of Loss
    Zilliqa did not immediately disclose the precise stolen quantity in its initial public communications on July 20; the figure emerged in subsequent disclosures and the official status page published July 24, 2026.
    reviewerZilliqa did not immediately disclose the precise stolen quantity on July 20; figure emerged with the July 24 status pageConfirmed.
  10. #13[confirmed][no action needed]in section: Stolen Funds and Scope of Loss
    KuCoin reportedly assisted in confirming ongoing exploitation and tracing the incident during the investigation.
    reviewerKuCoin reportedly assisted in confirming ongoing exploitation and tracing the incidentConfirmed; KuCoin was an assisting party in the investigation, not the (still unnamed) affected exchange.
  11. #16[confirmed][no action needed]in section: Market Impact
    The token hit an all-time low of $0.002441 during the incident period.
    reviewerZIL hit an all-time low of $0.002441 during the incident periodConfirmed.
  12. #17[confirmed][no action needed]in section: Market Impact
    By July 22, ZIL traded at approximately $0.0024, representing a 17% decline over the prior seven days.
    reviewerBy July 22, ZIL traded at approximately $0.0024, a 17% decline over the prior seven daysConfirmed.
  13. #18[confirmed][no action needed]in section: Market Impact
    Trading volume surged approximately 417% to around $20.78 million in the 24 hours after the disclosure, consistent with panic selling and opportunistic trading.
    reviewerTrading volume surged approximately 417% to around $20.78 million in the 24 hours after disclosureConfirmed near-verbatim.
  14. #19[confirmed][no action needed]in section: Market Impact
    ZIL was already trading approximately 99% below its May 2021 all-time high of approximately $0.2563, reflecting a prolonged bear market context preceding the incident.
    reviewerZIL was trading approximately 99% below its May 2021 all-time high of approximately $0.2563Confirmed by both the cited article and general market-data corroboration.
  15. #20[confirmed][no action needed]in section: Exchange Responses and Delisting Risk
    South Korean exchange Upbit took a more consequential step on July 22, 2026, designating ZIL as a cautionary asset across both its KRW and BTC markets, suspending deposits and withdrawals while maintaining spot trading temporarily.
    reviewerUpbit designated ZIL as a cautionary asset on July 22, 2026 across KRW and BTC markets, suspending deposits/withdrawalsConfirmed.
  16. #21[confirmed][no action needed]in section: Remediation and Recovery Plan
    Zilliqa suspended all native (non-EVM) ZIL transactions on July 21, 2026 as a protective measure.
    reviewerZilliqa suspended all native (non-EVM) ZIL transactions on July 21, 2026Confirmed.
  17. #23[confirmed][no action needed]in section: Remediation and Recovery Plan
    On July 31, 2026, Zilliqa announced a recovery and transition plan: the Zilliqa EVM environment would become the sole production network, with the legacy ZIL1 chain retired.
    reviewerOn July 31, 2026 Zilliqa announced a recovery/transition plan making Zilliqa EVM the sole production network, retiring ZIL1, providing migration toolsConfirmed, including the specific date.
  18. #24[confirmed][no action needed]in the timeline
    Zilliqa Ledger hardware wallet application released, containing a cryptographic flaw in Schnorr signature nonce generation that would persist undetected for over six years across all subsequent versions.
    reviewerZilliqa Ledger hardware wallet application released in 2019, flaw persisted undetected for over six yearsTechnically accurate ('over six years' is true of a ~7-year span), though some sources are more precise in calling it seven years.
  19. #25[confirmed][no action needed]in the timeline
    Suspicious on-chain activity consistent with active exploitation of the Ledger application flaw detected.
    reviewerSuspicious on-chain activity consistent with active exploitation detected on 2026-07-19Confirmed, though note this July 19 detection date understates that the underlying exploitation had reportedly been occurring since March 2026 (see coverage gap).
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.