Layer-1 network Zilliqa has suspended all native transactions after disclosing a vulnerability in its Ledger app that lets attackers reconstruct a user’s private key from information already recorded on the blockchain. The flaw affects every version of the app released since 2019, and the team says active exploitation was observed on July 19.

The bug sits in how the app generates Schnorr signatures for native, non-EVM Zilliqa transactions. “The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key,” Zilliqa said in a Wednesday post. Because the weakness leaks through signatures that are permanently public on-chain, any account that has broadcast about five or more native transactions signed with the Ledger app should be treated as compromised, regardless of any later software patch, Zilliqa said.

The disclosure follows a warning earlier in the week. Zilliqa on Monday asked exchanges to pause ZIL deposits and withdrawals after identifying a breach that resulted in the theft of an undisclosed amount of the token from a cold wallet. Major South Korean exchange Upbit has since designated ZIL a cautionary asset across its won and bitcoin markets, keeping deposits and withdrawals frozen and warning that trading support could be terminated if the issue is not resolved.

ZIL traded above $0.0024 on Wednesday, down roughly 19% over the week.

Zilliqa said protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized, including a corrected version of the app published in coordination with Ledger. Users who moved ZIL through EVM-compatible tooling are not affected.

For now, Zilliqa is telling anyone holding a potentially exposed key to wait for instructions before taking any action.

Related Listen: The Chopping Block: Zcash Infinite Mint Bug + AI Hackers vs Formal Verification + NEAR’s Agent Vision