Major South Korean cryptocurrency exchange Upbit has flagged Zilliqa ($ZIL) as a cautionary asset following the discovery of a critical vulnerability in its Ledger application.
According to Wu Blockchain, Upbit has placed $ZIL under cautionary asset status, raising concerns over the token's future trading support on the crypto exchange, with the possibility of delisting it if the security issue isn't resolved.
Zilliqa Ledger App Flaw Exposes Private Keys, Upbit Flags $ZIL as a Cautionary Asset
— Wu Blockchain (@WuBlockchain) July 22, 2026
Zilliqa disclosed a critical nonce-generation flaw in its Ledger app that allows private keys to be recovered from public signatures after about five native transactions. The issue affected all… pic.twitter.com/uMfV9ZbepR
Earlier today, July 22, Zilliqa disclosed a critical nonce-generation flaw in its Ledger app that allows private keys to be recovered from public signatures after about five native transactions.
The issue affects all versions released from 2019 to 2026, with active exploitation observed on July 19. Native Zilliqa transactions have been suspended, with affected keys set to be retired, while EVM transactions are unaffected.
Upbit subsequently designated $ZIL as a cautionary asset across its KRW and BTC markets. $ZIL deposits and withdrawals remain suspended, and trading support may be terminated if the issue is not resolved.
What happened?
On July 22, Zilliqa announced the discovery of a nonce-generation vulnerability in its Ledger app in an X post.
A critical vulnerability was identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key using only publicly available on-chain data.
The Zilliqa team noted that protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalized.
The vulnerability affects private keys used to sign native Zilliqa transactions with a Ledger device, and any account that has broadcast about five or more native transactions signed through the Zilliqa Ledger app should be considered compromised. This is because their private keys can be reconstructed from signatures already recorded on-chain, regardless of any subsequent software update.
The issue is, however, confined to the Ledger app's native signing path, with EVM transactions unaffected.