Zilliqa says a bug in how its Ledger hardware wallet app signed transactions exposed at least 6,772 user accounts and enabled the theft of 683 million ZIL. The blockchain project disclosed the details in a post-mortem, describing a flaw tied to how the app handled the secret data that protects private keys.
According to Zilliqa’s post-mortem, a signing bug in its Ledger app left a minimum of 6,772 accounts exposed. A signing bug means the wallet app mishandled the process of approving transactions, the step meant to keep your funds safe. For related coverage, see Illinois crypto tax lawsuit faces second challenge.
Zilliqa says the same flaw enabled the theft of 683 million ZIL, the network’s native token. The company frames 6,772 as a minimum figure, not a confirmed final total of everyone affected. For related coverage, see Cleveland Fed: Bitcoin's 12-Month Gains Attract New Crypto Investors.
Reporting from CryptoSlate traced the issue to the hardware wallet app discarding entropy. Entropy is the randomness used to generate a private key; without enough of it, keys become guessable, which can expose the crypto they protect. For related coverage, see Trump Hosts White House Crypto Summit Amid CLARITY Act Push.
Why the Account Count and Token Loss Matter
The 6,772 figure gives a measurable floor for how many users were caught up in the incident. Because Zilliqa calls it a minimum, the real number of impacted accounts could be higher.
The stolen tokens point to the financial weight of the bug. A signing flaw sits at the trust layer of any wallet, so a failure there directly threatens user funds and confidence in ZIL.
The bug was serious enough that Zilliqa halted native transactions on the network, according to The Block, which reported the flaw dated back to the Ledger app’s 2019 code.
What Zilliqa Users Should Take Away
If you held ZIL through a Ledger device, your account may sit inside that exposed group. The incident is a reminder that even hardware wallets, widely seen as the safer option, can carry app-level flaws.
This is not the first time signing has drawn scrutiny in the Ledger ecosystem. Ledger previously moved to patch a separate issue when it fixed an Ethereum signing vulnerability, underscoring how the approval step keeps surfacing as a weak point.
The pattern echoes other projects that paused operations after a code-level problem, much like when TAC halted block production over a token supply exploit. Stopping the network buys time but signals how deep the underlying flaw runs.
For regular holders, the practical point is simple: watch official Zilliqa channels for guidance and confirm whether your account falls within the disclosed exposure before moving funds.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.