TLDR
Zilliqa said on August 20, 2026 that the legacy Zilliqa Ledger application had leaked key material through repeated public signatures, with the post-mortem recording 683,130,969.66 ZIL of proven theft across 66 transactions and 6,772 exposed accounts, of which 51 were drained. Legacy transactions are paused, the network is moving exchange and user balances toward Zilliqa EVM, and exchange-managed legacy addresses are expected to be deny-listed during the migration. For exchange users, the practical question is simple: do not send ZIL until your venue publishes the correct reopening instructions, the correct deposit path and the correct address format. The scam window around any migration is now wider than usual.
Key takeaways
- Zilliqa's post-mortem says exploitation began on March 4, 2026 and the last theft transaction was on July 20, 2026 before legacy transaction functionality was disabled later that day.
- Zilliqa says the flaw affected only signatures produced by the legacy Zilliqa Ledger application, not Zilliqa EVM activity, not software SDK signatures and not other blockchains on the same Ledger device.
- Zilliqa's incident page says exchange-held ZIL is a separate situation because exchange balances are controlled by the exchange, but deposits and withdrawals may stay paused until migration and integration checks are completed.
- The exchange migration FAQ says exchange balances are intended to move 1:1 to EVM-compatible addresses and that legacy exchange deposit, hot and cold wallets will be deny-listed as part of the migration.
- Zilliqa said on August 11, 2026 that it was targeting the first batch of exchange migrations by the end of August, but timelines may vary by venue.
- CryptoGuide Exchange is an independent research and comparison platform, not an exchange, broker, custodian, investment adviser or legal adviser.
What happened
Zilliqa's explanation matters because it rules out some common crypto-incident assumptions. The project says users were not phished, their Ledger devices were not generically broken and their recovery phrases were not stolen. Instead, the weakness sat in the legacy Zilliqa Ledger app's signing path. Repeated signatures leaked enough information for attackers to reconstruct a private key after a wallet had signed several affected transactions.
That turns this into a market-infrastructure issue as much as a wallet issue. Once the legacy path became unsafe, Zilliqa paused legacy transactions, prepared a migration toward EVM-compatible addresses and started coordinating with exchanges on deposit, withdrawal and address-mapping changes. That is why exchange users should care even if they never touched a Ledger.
How the attack flow matters for exchange users
- A legacy Zilliqa wallet signed multiple transactions through the affected Ledger app.
- Attackers reconstructed some private keys from the public signatures on-chain.
- Zilliqa disabled legacy transaction functionality on July 20, 2026 to stop further exploitation.
- The ecosystem shifted into migration mode: exchanges now need to map legacy addresses to EVM-compatible ones before deposits and withdrawals normalize.
- Users face a new risk window where outdated deposit addresses, copied legacy addresses or fake migration messages can turn confusion into lost funds.
What changes for exchange users now
| Area | What the sources say | Why users should care |
|---|---|---|
| Deposits and withdrawals | Zilliqa says the first batch of exchange migrations is targeted by the end of August 2026, after integration checks. | Your venue may reopen at a different time from another venue, so generic social-media claims are not enough. |
| Address format | The exchange FAQ says balances will migrate from legacy Schnorr-based addresses to fresh EVM-compatible addresses. | Old deposit instructions can become wrong fast, even if the ticker remains ZIL. |
| Legacy addresses | The FAQ says legacy exchange deposit, hot and cold wallets will be deny-listed as part of the migration. | Sending to an old address after the hard fork may fail or be rejected. |
| Balance migration | The FAQ says exchange account migration is intended as a 1:1 balance reassignment at the protocol state level during the hard fork. | This is an infrastructure transition, not a launch of a new exchange-wrapped token for retail users. |
| Scam exposure | Zilliqa warns users not to trust DMs and says only official channels will announce tools or next steps. | Migration headlines create ideal conditions for fake support, fake recovery portals and copy-paste address fraud. |
User checklist before sending or withdrawing ZIL
| Check | Why it matters | What to do |
|---|---|---|
| Venue-specific status | Zilliqa's own target dates are ecosystem-level, not a promise for your exchange. | Use your exchange's status page, deposit page or help center before acting. Do not rely on screenshots or forwarded posts. |
| Deposit address type | The migration changes which address format is valid for exchange-managed balances. | Generate a fresh ZIL deposit address inside the exchange after reopen, even if you still have an older saved address. |
| Test transfer | Any chain or address migration raises avoidable user-error risk. | Send a small test amount first, wait for full credit, and only then move a larger balance. |
| Withdrawal timing | Early reopen periods can involve maintenance pauses or slower reviews. | If a transfer is not urgent, wait for your venue to confirm stable operations rather than rushing the first minute it reopens. |
| Private messages | Recovery and migration events attract impersonators. | Ignore any DM, email or Telegram message offering a migration form, recovery link or manual address fix. |
| Self-custody distinction | Exchange-held ZIL and self-custodied legacy ZIL do not follow the same support path. | If your ZIL was on an exchange, speak to the exchange. If it was in your own affected legacy wallet, use only Zilliqa's official incident resources. |
Risk notes users should not gloss over
Paused does not mean stolen, and resumed does not mean foolproof
Zilliqa stresses that paused legacy transactions do not mean every holder was affected. The reverse is also true for exchange users: once a venue reopens ZIL transfers, that does not eliminate address-format mistakes or fake-support attempts around the migration.
There is no new retail token to chase
The exchange FAQ explicitly says there are no new tokens or token contracts for exchange users and that ZIL remains the network's native coin. That matters because migration events often attract fake token-claim pages and bogus "swap now" instructions.
One ZIL market can hide different operational states
ZIL may keep trading on exchanges while deposits and withdrawals remain unavailable or partially restored. Users should separate market access from transfer access and avoid assuming that a live order book means the infrastructure transition is finished.
How Zilliqa says the response works
The incident page says legacy transaction functionality was disabled on July 20, 2026, the exposed-account population was identified from public chain data on July 22, an address checker went live on August 11, and the project is pursuing a universal migration to Zilliqa EVM rather than reopening the legacy signing path. The exchange migration FAQ adds that exchanges should submit all legacy operational and deposit addresses, that migration is intended to happen during a single network-wide hard fork, and that legacy exchange addresses will be deny-listed as part of that process.
CryptoGuide take
The most useful part of the Zilliqa response is not the headline theft number. It is the decision to write down the mechanics, the limits and the unknowns clearly. Exchange users should copy that posture. Treat ZIL reopening as an operations event, not a trading event. The right trust signal is precise venue guidance about deposit paths, address generation and timing. The wrong signal is fast-moving social hype about a "new ZIL" or a shortcut migration link.
FAQ
Are exchange-held ZIL balances affected by the Zilliqa Ledger flaw?
Not in the same way as self-custodied legacy Ledger wallets. Zilliqa says exchange-held ZIL is a separate situation because the exchange controls the signing path, but deposits and withdrawals can still stay paused until the exchange completes migration work.
What did Zilliqa say happened in the August 20, 2026 post-mortem?
Zilliqa said a flaw in the legacy Zilliqa Ledger application leaked enough information through public signatures for private keys to be reconstructed after repeated signing. The post-mortem records 683,130,969.66 ZIL of proven theft across 66 transactions and 6,772 exposed accounts, of which 51 were drained.
What should users verify before sending ZIL when transfers reopen?
Verify that your exchange has published the correct Zilliqa EVM deposit details, check whether legacy addresses are deny-listed, test with a small transfer first, and ignore any private migration or recovery link sent through DMs or email.
Conclusion
As of Wednesday, August 26, 2026, the Zilliqa story is no longer only a wallet post-mortem. It is an exchange-operations transition with real user-error risk around deposit addresses, reopen timing and scam attempts. The calm move is to wait for venue-specific instructions, generate fresh addresses when needed and treat every unofficial migration shortcut as hostile.
Related pages
- Exchange withdrawal protection in 2026
- Trezor shipping-provider breach: what self-custody users should do now
- How to avoid crypto scams
- What is a crypto wallet?
- Run a trust check