Legacy transactions: pausedUpdated 11 August 2026, 12:00 UTC

Ledger security incident

A signing flaw was found in the Zilliqa Ledger app, so all legacy transactions are paused and nothing can move right now, not yours and not an attacker’s. Being paused does not mean you are affected, and most people who are paused are not.

Latest updateThe address checker is live
  • Nothing can moveEvery legacy transaction is paused, so funds cannot leave any wallet while the pause is in place, including an attacker’s.
  • Paused is not affectedEveryone on the legacy side is paused, even people who never touched a Ledger. Most of them are not affected at all.
  • There is a way forwardEveryone on the legacy side will be invited to migrate to Zilliqa EVM, and a recovery route is being built for holders of affected accounts. The plan.

One important distinction

One distinction governs every section below.

Legacy ZilliqaThe older, non-EVM side of Zilliqa: its accounts, its transactions, and the Zilliqa Ledger application built for it.
Zilliqa 2 (EVM)The newer, EVM-compatible side of Zilliqa.

This incident affects only the legacy side. Throughout this page, “legacy” means the older, non-EVM Zilliqa. Zilliqa EVM is not affected.

Am I affected?

Check your address against its own public signature history, or answer two questions instead. The checker cannot see everything, signing done off-chain leaves no trace on the chain, so the questions below still matter whatever result you get.

Check an address

Live

Enter your legacy Zilliqa address (ZIL1...) to check whether it was affected by the incident or may be vulnerable because of signatures produced through the Zilliqa Ledger application.

You do not need to connect your wallet or provide your seed phrase, private key or recovery phrase.

Checking sends the address, and nothing else, to Zilliqa’s server to run the search. It is answered and forgotten: the address is never logged or stored, and no list of checked addresses exists.

or answer two questions instead

1Have you ever used the Zilliqa Ledger app on a Ledger device to sign a transaction of any kind, sending ZIL, moving ZRC-2 tokens or NFTs, or staking?

Whatever the checker or the questions say, no legacy funds can move while transactions are paused, including from affected wallets.

What happened

A security flaw was found in the Zilliqa Ledger application, the app built to sign transactions on the legacy, non-EVM side described above. Because of this flaw, every transaction signed through that app quietly gave away a small piece of information about the wallet’s private key. No single transaction revealed enough to matter, but once a wallet had signed several of them, someone who collected those transactions, which are public on the blockchain, could piece the key together and take the wallet’s funds.

That is why some wallets were emptied without their owners doing anything wrong: nobody was tricked, no device was hacked, and no recovery phrase was stolen. The information leaked through the transactions themselves.

What decides whether a transaction is affected is how it was signed, not when. Only signatures produced by the Zilliqa Ledger app leaked information: a legacy transaction signed another way, for example through the software SDKs, is not affected, and neither is any Zilliqa EVM activity. The flaw is in that one app; the Zilliqa network itself processed every transaction as designed.

Who is affected and who is not

You are not affected if

  • you have never used a Ledger device with Zilliqa;
  • you used a Ledger, but never with the Zilliqa Ledger application;
  • you only ever made EVM transactions;
  • you signed only through the software SDKs, zilliqa-js, gozilliqa-sdk and pyzil generate signatures correctly and are not affected; or
  • you stake through the official Zilliqa staking portal (stake.zilliqa.com).

You may be affected if

  • you used the Zilliqa Ledger application to sign transactions, of any kind, not only sending ZIL;
  • that includes sending native ZIL, moving ZRC-2 tokens (ordinary and non-fungible), and staking or unstaking.

When an account is at risk

Every version of the Zilliqa Ledger application is affected, so this does not depend on which version you used. The risk applies to accounts that signed at least four such transactions, that is around the point where the private key can be reconstructed from the public signatures.

Check your address

The live checker in the “Am I affected?” section reads an address’s public signatures and shows any evidence of exposure it can find, so you can confirm your own situation here rather than through support.

What is not at risk

Your recovery phrase, the words you wrote down when you set up your Ledger, was not exposed by this flaw. Because of that, the only thing that can be at risk is the key to the individual legacy Zilliqa account, rebuilt from its own public signatures. Your Ledger as a whole is not compromised, and funds you hold on other blockchains on the same device, Ethereum and ERC-20 tokens, Solana, anything else, are not at risk. The flaw reaches one signing path and no further.

What if my ZIL is staked?

If your ZIL is staked and earning on Zilliqa EVM, the EVM side of Zilliqa, it is safe: that side is not affected.

If your ZIL is parked in a legacy staking portal or contract, it is paused along with everything else on the legacy side, and it will need the recovery path once that is ready.

Reporting a wallet you believe was affected

If you believe a wallet was affected, you can report it to us. Reporting opens a prefilled email in your own mail app, with our address already written in. This form stores nothing and sends nothing on your behalf. It asks for one thing, the address, and nothing else.

Reporting an address is not a claim for compensation, and we cannot promise an individual reply to every report. What it does is help us build a fuller picture of which accounts were touched.

Opens your email app with the details prefilled. This form itself sends nothing to any server.

If the button does not open your email app, report it directly:enquiry@zilliqa.com

We will never DM you after a report, and we will never ask for your recovery phrase.

Do not trust DMs

Incidents like this bring out impersonators offering to “help” you recover your funds. Please be careful.

The Zilliqa team will never contact you first, and will never ask for your seed phrase, private key or recovery phrase, for any reason, ever.

Treat any recovery tool, form or link sent to you privately as hostile, even if it looks official or seems to come from a moderator. Block it, and report it.

The only tools we will ever ask you to use are the ones announced on the official accounts at the end of this page.

What is being done

  • Legacy transactions are paused. This stops any further movement. On its own it does not protect a key that is already exposed, which is why the steps below matter.
  • The cause has been found and confirmed. A corrected build is being prepared in coordination with Ledger; it protects new accounts going forward, and it does not undo exposure on accounts that have already signed. Those keys will need to be retired.
  • Affected wallets are being identified from public blockchain data. This is the same work that powers the address checker above.
  • A recovery path is being built. The aim is to let people who hold affected accounts move recoverable funds to a fresh address by proving they own the account without ever revealing their seed phrase, a zero-knowledge approach.
  • We are not doing this alone. We are coordinating with exchanges and the relevant authorities to trace the funds and the person responsible.

None of these items carries a date, deliberately. We would rather do each one properly than name a day we cannot keep.

The plan from here

The steps above are the immediate response. This is the direction beyond it, published on 11 August 2026, 12:00 UTC.

Recovery runs through migration, not reopening

Rather than reopening the legacy side, the transition to Zilliqa EVM that was already under way will be completed. Zilliqa EVM becomes the only production side, and every legacy wallet holder will be invited to migrate to it, affected or not. Migrating everyone, rather than only the wallets this incident touched, removes the uncertainty about who stands where and gives everybody the same secure starting point.

  1. Complete the move to Zilliqa EVM

    The legacy environment was designed for a different security landscape, and keeping it running alongside Zilliqa EVM costs effort that the network’s future needs. The incident brings forward a transition that was already under way; Zilliqa EVM becomes the sole production side.

  2. Open migration to every legacy wallet

    Every legacy wallet holder will be invited to migrate to Zilliqa EVM with an official migration tool, whether or not they were touched by this incident. Migrating everyone removes the guesswork and gives the whole ecosystem the same secure starting point.

  3. Migrate the ecosystem, not just wallets

    Exchanges, wallet providers, custodians and infrastructure partners will be supported through the move of deposits, withdrawals and integrations, with engineering help throughout, so the transition is coordinated rather than piecemeal.

  4. Strengthen Zilliqa EVM

    The validator set, network governance and operational infrastructure will be reviewed and strengthened as part of the transition; legacy components are retired rather than carried forward.

  5. Build a fair recovery framework

    Affected holders should have a clear, practical route into a recovery programme. The way ownership is verified is still being designed, with the aim of collecting as little personal data as possible while still giving confidence that a claim is genuine. At the current stage the total amount stolen is estimated at ZIL 683,130,969.66.

  6. Update the tokenomics framework

    An updated tokenomics framework restores balances held on the retired side, keeps validator incentives uninterrupted, and sustains the network through the transition.

  7. Keep pursuing the stolen assets

    Work continues with law enforcement, exchanges, blockchain analytics providers and ecosystem partners to recover what can be recovered. Legal action will stay targeted and proportionate, weighed against what it can realistically achieve.

  8. Keep communicating in the open

    The community, exchanges and partners will get regular updates through the transition, covering not only what is being done but why. This page is where each of those updates is written down.

  9. Hold to the long-term strategy

    The incident does not change the direction of the protocol; it makes the case for executing it more decisively. With the legacy side retired, development refocuses on Zilliqa EVM and on the institutional infrastructure the protocol was already being built toward.

One thing worth being plain about. None of this carries a date yet, for the same reason nothing above does: we would rather do each piece properly than name a day we cannot keep. When a step is settled, or when the migration tool is ready, it will appear in Updates with the date and what changed.

Where things stand

Progress against that plan, as of 11 August 2026, 12:00 UTC.

Migration tool entering external security audit:

The migration tool is expected to undergo an external security audit over the next two weeks. We currently expect the audit report to be available by the beginning of September.

Once the findings have been reviewed and any required work has been completed, we expect to be able to announce a launch date for the migration tool. Security comes before speed, and the final timeline will depend on the outcome of the audit.

Exchange migration progressing:

Discussions with exchange partners are progressing well, and several exchanges have already confirmed that they will support the migration.

We are targeting the first batch of exchanges to migrate by the end of August. This is expected to enable participating exchanges to resume ZIL deposits and withdrawals on Zilliqa EVM once their migration work and integration checks are complete. Timelines may vary between exchanges.

Investigation and asset-tracing efforts continue:

Work to trace the stolen funds continues in coordination with the appropriate legal authorities, exchange partners and other relevant parties.

Given the serious nature of the incident and the involvement of legal authorities, we are unable to share further details at this stage. We will publish additional information when we are legally permitted to do so and when sharing it will not compromise the investigation.

What if my funds were lost?

If you have lost funds, we understand what that means, and we are sorry you are going through it.

We are working with exchanges and the relevant authorities to trace the funds and the person responsible, and to work out the best way forward for everyone affected. If there is anything to share on this, it will appear here first.

If you hold ZIL on an exchange

If your ZIL sits on an exchange, it is held by the exchange, not signed by you on a Ledger, so this is a separate situation from everything above. For the status of those funds and what to do next, your point of contact is the exchange’s own support.

For exchange teams working through the migration, the answers we give partners are published in the exchange migration FAQ, which is kept up to date as new questions are answered.

Exchanges with questions not covered there can reach us privately at enquiry@zilliqa.com.

Official accounts

These are the only accounts that speak for Zilliqa about this incident. Anything that is not listed here is not us.

Last updated 11 August 2026, 12:00 UTC. See what changed.

Updates

This page is the record for this incident. Every update is logged here, newest first, with the date it was published and what changed; if it is not written down here, it did not come from us.

  1. 11 August 2026, 12:00 UTCLatest

    The address checker is live

    You can now check a Zilliqa address against its own public signature history, on this page, without going through support. Alongside it, "Where things stand" publishes the position on the migration tool audit, the exchange migration and the asset-tracing work, as issued.

    What changed

    • Added "Where things stand", the position on the migration tool audit, the exchange migration and the asset-tracing work, in full and unedited.
    • Added the live address checker to the "Am I affected?" section. It reads an address’s public signatures and reports one of four results, each with the reservations that belong to it. A result other than compromised is not a clean bill of health, and signing done off-chain leaves no trace it can see.
    • The guided self-check stays alongside it: off-chain signing leaves no on-chain trace, so the two questions still matter whatever the checker says.
    • Reordered the page so "Am I affected?" comes first and this update log now lives at the end.
    • Added the exchange migration FAQ at /ledger-incident/exchanges-faq/ (published 5 August), covering address mappings, deny-listing, hard fork timing and the recovery process for exchange-controlled wallets, and linked it from "If you hold ZIL on an exchange".
    • No change to the immediate situation: legacy transactions remain paused, and there is nothing you need to do right now.
  2. 31 July 2026, 10:00 UTC

    Recovery and transition plan published

    The way forward has been set out: the legacy side is being retired, Zilliqa EVM becomes the only production side, and every legacy wallet holder will be invited to migrate, whether or not they were affected by this incident.

    What changed

    • Added "The plan from here", the nine-point recovery and transition plan, to this page.
    • Confirmed that recovery now runs through a universal migration to Zilliqa EVM, rather than reopening the legacy side.
    • No change to the immediate situation: legacy transactions remain paused, the address checker is still being built, and there is nothing you need to do right now.
  3. 24 July 2026, 16:00 UTC

    This status page went live

    The incident, who it reaches and who it does not, and the work under way were published in one place, so nobody has to piece the position together from social posts.

    What changed

    • Published what happened, who is affected and who is not, and what is being done.
    • Added the guided self-check, which works out where you stand from what you did rather than from your address.
    • Added a way to report a wallet you believe was affected, and the list of accounts that speak for Zilliqa about this incident.