Zilliqa Vulnerability and Cross-Chain Theft: A New Alarm for Crypto Security

CN
1 hour ago

Zilliqa acknowledged on July 22, 2026, that its Ledger application contained a vulnerability in the implementation of Schnorr signatures for native ZIL transactions, where the high 64 bits of temporary random numbers had been permanently zero since 2019. Affected users could potentially expose their private keys with just a few transactions under extreme circumstances, forcing the project team to urgently suspend all native ZIL transactions while emphasizing that EVM-compatible transactions remained unaffected. Almost simultaneously, alarms were raised in the cross-chain field: on a Monday, Wanchain's cross-chain bridge experienced a security incident, with approximately 290 million NIGHT tokens being concentrically transferred out, causing a price drop of about 43%, followed by a near 19% recovery within 24 hours. Charles Hoskinson even cited the accident partly to the historical issues related to third-party legacy cross-chain bridge architecture. Meanwhile, outside of the blockchain, Dongshan Precision confirmed that light modules in its overseas warehouse were stolen. Although the financial loss was far less than the rumored tens of millions of dollars and did not meet mandatory disclosure standards, the company's official stance stated that the impact on profits was limited, while no specific details regarding the stolen quantity and warehouse location were revealed. These seemingly scattered events pointed to a common thread: long-standing vulnerabilities in critical infrastructure, latent risks of third-party components, and the boundaries of corporate disclosure regarding security incidents are simultaneously under scrutiny, forcing the market to recalibrate security expectations concerning hardware wallets, cross-chain bridge architectures, and information disclosure systems.

Zilliqa Ledger Random Number Trap

Behind Zilliqa's announcement lies an implementation error that is virtually unacceptable from a cryptographic perspective: according to a single source, when generating Schnorr signatures for native ZIL transactions, the high 64 bits of temporary random numbers on the Ledger Zilliqa application were permanently zero. On the surface, this is just an “invisible” bit-level bug, as users only see normally broadcasted on-chain transfers; however, since 2019, this structurally entropic random number has been continuously written into blocks, becoming a public sample that attackers can repeatedly exploit. Hardware wallets are regarded as the “last line of defense,” and the prolonged oversight of application-layer random number generation directly exposes the black box areas in the device manufacturer and on-chain application audit processes.

Research indicates that under this random number model, an attacker theoretically needs to collect only about 5 native ZIL transaction signatures from affected addresses to recover the corresponding private keys within seconds. Once the private key is restored, all assets on the related address are no longer protected, and all subsequent authorizations and transfers can be forged, with the chain's historical transactions themselves becoming the decryption key. The finer boundary here is that the vulnerability only affects native (non-EVM) ZIL transactions initiated through the Ledger application, while EVM-compatible transactions remain unaffected. This “selective exposure” leaves some users in a high-risk position without their knowledge and forces the market to reconsider: if so-called hardware-level security does not involve continuous and independent audits of critical parameters like underlying random numbers, even the sturdiest devices can become invisible security traps due to a line of implementation code.

Suspension of Native ZIL and EVM Transactions Remain Unaffected

After officially acknowledging the defects in Ledger's random number implementation, Zilliqa opted for a nearly “emergency brake” response: announcing the suspension of native ZIL transactions to repair the vulnerabilities and assess risks without generating new potentially high-risk signatures. This means that basic operations such as ordinary transfers and asset adjustments between accounts relying on the native path have been paused; once users are already exposed to affected signatures, they find it difficult to continue using the native channel in the short term and also face challenges in quickly migrating on-chain for self-rescue.

In stark contrast, the official announcement repeatedly emphasized that ZIL transactions on the EVM-compatible path were unaffected by this Schnorr random number issue. In other words, there suddenly emerged an operational disconnect between native addresses and EVM-compatible addresses: some users could continue to interact seamlessly through EVM contracts and applications, while others were left waiting for repair and remediation solutions. As there is currently no publicly disclosed vulnerability remediation timetable and specific user remediation arrangements, this structural difference of “native suspension, EVM unaffected” has directly compressed normal activities on the native chain in the short term, forcing confidence surrounding Zilliqa's native ecosystem to undergo a reality check.

Wanchain Theft and NIGHT Roller Coaster

At the same time as Zilliqa chose to hit the pause button on its native chain, a security vulnerability was revealed at the other end of the multi-chain world: Wanchain's cross-chain bridge was compromised. On Monday, a bridge that facilitated the cross-chain circulation of NIGHT assets was breached, with around 290 million NIGHT tokens being unusually transferred out, and the passage initially designed for seamless cross-chain traversal instantly became an exit for massive chips to be extracted. The vulnerability of this “connection layer,” the cross-chain bridge, was extremely directly laid before everyone.

Reports indicate that after the incident, the price of NIGHT dropped by approximately 43%, then rebounded by nearly 19% within 24 hours, depicting a roller coaster trajectory of panic selling and rapid speculation. Particularly alarming was the fact that this volatility did not stem from a sudden degradation of the project's fundamentals but rather from the collapse of underlying cross-chain infrastructure. Charles Hoskinson, in his comments, attributed part of this incident to problems with the third-party legacy cross-chain bridge architecture, highlighting a disconcerting reality for the industry: many projects' cross-chain pathways still deeply rely on external and often old solutions that had not been thoroughly reconstructed for years. Current public information has not disclosed specific technical details of the vulnerability or the identity of the attackers, but in the current lack of clarity, this incident surrounding third-party cross-chain bridge architecture is already enough to remind the market that the multi-chain connection layer itself is becoming a core security boundary that must be confronted.

Theft of Dongshan Precision's Warehouse and Information Gaps

Compared to the technical vulnerabilities associated with cross-chain bridges and wallet applications, the security incident at Dongshan Precision appears more “traditional”: the company confirmed that light modules were stolen from its overseas warehouse, drawing attention from investors and the media. However, during the rapid amplification of public opinion, the market circulated rumors that the losses amounted to tens of millions of dollars, prompting Dongshan Precision to clarify that the stolen amount was far below related rumors and emphasized that this loss did not meet the mandatory disclosure standards for the securities market, having a limited impact on overall profits. In publicly available information, the specific number of stolen light modules and their warehouse location has not been disclosed, leaving a difficult-to-fill information vacuum even as the incident has been officially confirmed.

This mirrors the two different pressure structures regarding the disclosure of security incidents between traditional manufacturing companies and crypto projects: the former primarily needs to connect with regulatory rules and the accounting significance of “materiality,” allowing them to maintain a restrained disclosure as long as losses do not hit thresholds; the latter, however, is compelled to provide immediate responses under the magnification of on-chain records, community opinions, and asset prices, even when the technical details have not been clarified. Dongshan Precision has chosen to manage its risk narrative by stating it “does not constitute mandatory disclosure,” while Zilliqa and cross-chain projects must publicly acknowledge problems at a stage when the causes and scope of the vulnerabilities are still being investigated. This discrepancy in information gaps and disclosure pacing serves as a mirror for understanding the differing safety cultures of various infrastructures.

Where Will the Next Security Thunder Strike?

The Zilliqa Ledger random number vulnerability, lying dormant since 2019 before being revealed, indicates that even with years of native ZIL transaction records on the chain, security audits may still overlook such long-tail defects; the theft of Wanchain's NIGHT is pointed to being related to third-party legacy cross-chain bridge architecture, turning old components and outsourced modules into “dark boxes” recalled only in hindsight; Dongshan Precision downplaying the impact of the warehouse theft with “not reaching disclosure standards” reveals a misalignment between institutionalized information disclosure and market sentiments. These three incidents point to the same unsettling conclusion: the next security thunder may very well hide in implementation details that have gone untouched for years, rather than in the price curves on-chain that we are accustomed to monitoring. For average users, when choosing hardware wallets and cross-chain bridges, it is not enough to simply consider brands and claimed degrees of decentralization; it is crucial to actively ask whether specific implementations have undergone continuous audits, if there have been any recent security announcements, and whether teams are willing to prioritize alerting risks when incidents occur even if technical details are not fully clarified. As of July 22, 2026, the resolution of the Zilliqa vulnerability and impact assessment, adjustments paths made by Wanchain regarding legacy architecture, and the disclosure stance of Dongshan Precision in relation to the security incident have yet to reach a conclusion, and these subsequent actions will be key references for observing the direction of infrastructure security culture and risk narrative in the next round.

Join our community to discuss and grow stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink