Quick Take
  • The trigger was a critical Ledger flaw that exposed users’ private keys.
  • Zilliqa is a layer-1 blockchain that launched in 2019.
  • On Wednesday, it revealed that every version of its Ledger wallet app since launch carried the bug.
  • It zeroed out part of the random number that protects each signature.

What Happened

Zilliqa is a layer-1 blockchain that launched in 2019. On Wednesday, it revealed that every version of its Ledger wallet app since launch carried the bug.

Exploitation began on July 19. A day later, an exchange partner reported ZIL stolen from a cold wallet. KuCoin then helped trace the bug, confirmed on July 21. The episode joins a string of key compromise attacks this year.

Upbit acted under Korea’s Virtual Asset User Protection Act, a 2024 investor safety law. The tag covers the ZIL/KRW and ZIL/BTC pairs. Deposits and withdrawals have been frozen since July 20, per the exchange’s notice. The review runs until the week of August 17.

Market Context

Upbit Review Puts ZIL Trading Support at Risk

Risk labels like this often hit prices hard. Wanchain fell 34% after Binance’s monitoring tag. Flow’s backers even went to court over Korean exchange delistings.

ZIL now trades near $0.0025, per ZIL markets data. It hit a record low of $0.00235 on Wednesday. The token is down about 17% in a week and 99% from its May 2021 peak. Its market cap sits near $49 million.

Zilliqa has promised a recovery plan for affected balances. What that plan delivers may decide whether Upbit lifts the watch or ends trading support.

Why It Matters

The post Upbit Puts Altcoin at Risk of Delisting Following Critical Ledger Flaw appeared first on BeInCrypto.

Details

Upbit has put Zilliqa (ZIL) on delisting watch. The trigger was a critical Ledger flaw that exposed users’ private keys. ZIL fell about 10% as traders reacted.

How the Ledger Flaw Exposed Zilliqa Private Keys

The app made a simple copying mistake. It zeroed out part of the random number that protects each signature. That leak adds up fast. After roughly five native transactions, attackers can work out a private key in seconds on an ordinary computer.

“Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should be considered compromised,” Zilliqa said in its disclosure.

Native ZIL transfers are now suspended. Affected keys must be retired because the leaked signatures live on-chain forever. Ethereum Virtual Machine (EVM) transactions and software wallets are safe.