EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Zilliqa cooperative exchange's cold wallet was hacked, ZIL recharge was suspended

2026-07-21 00:52:17
Bookmark

A security incident forced Zilliqa to suspend ZIL withdrawals from all centralized exchanges.

A security incident involving one of Zilliqa's exchange partners led the network to require all centralized platforms to suspend ZIL token repayments and withdrawals, thus freezing the liquidity of native tokens in one of the industry's earliest fragmented blockchains. The breach was initially reported by a media and the target was cold wallets, which immediately raised a question: How was the offline storage system compromised?

Zilliqa's team confirmed that the stolen funds were ZIL tokens stored in the cold wallet of the partner exchange, but did not disclose the name of the exchange and the specific amount stolen. In a public statement, the project said it was working with affected parties and other stakeholders to determine the root cause and the full scope of losses. The temporary suspension of top-ups and withdrawals from all centralized exchanges is a deterrent designed to prevent attackers from transferring or selling stolen assets through regulated order books.

Invasion confirmed, but few details

The absence of key details means traders and liquidity providers can only grope in the dark. Cold wallet theft is extremely rare because it often requires physical contact, insider leaks, or a complex attack on the hosting infrastructure that ultimately connects the wallet to the hot system to process withdrawals. Zilliqa did not say whether the cold wallet belonged to a large exchange or a smaller regional partner, which left huge uncertainty about the potential market impact.

Launched in 2017, this chain, although it was an early adopter of sharding technology, still faces various technical and adoption challenges. Projects that have been running for nearly a decade often rely on a few exchanges to provide liquidity, so even a single partner intrusion could affect the entire market. ZIL is listed on many major exchanges, and the freezing of recharge means that arbitrageurs and market makers cannot adjust their positions, which may lead to widening spreads or temporary market misalignments after trading resumes.

Cold wallets are not always safe

Cold wallets should be immune to network-based attacks because their private keys are stored offline. But recent history shows that even offline environments have vulnerabilities. In 2024, WazirX lost more than $230 million due to the theft of multi-signed cold wallets, which investigators believe was a combination of social engineering and offline signers being breached. Although this incident has nothing to do with that, the pattern of cold wallet intrusion has upset the market, which has been told for years that offline storage equals security.

The case is particularly opaque because Zilliqa's disclosure referred to the victim as an "exchange partner," which most likely meant a third-party custodian or liquidity provider using Zilliqa's infrastructure. The lack of transparency is not necessarily suspicious-forensic investigations often require confidentiality-but it fuels anxiety. If the vulnerability stems from Zilliqa's own transaction signature or multi-signature logic, it will be a systemic risk; if it is just an exchange-level operational error, the damage may be more limited.

As global institutions push for clearer custody rules-a debate that is reflected in legislation such as the U.S. GENIUS Act, while banks are trying to kill the largest cryptocurrency bill-such incidents provide arguments for those who require exchanges to meet bank-level security standards. This incident also occurred when some altcoin foundations were actively promoting their chains to institutional pledge services. Cold storage failures can erode the trust on which institutional interests depend.

Market Freeze and Ecosystem Reaction

ZIL's on-chain activities have not been affected; the blockchain itself processes transactions as usual. The freeze only applies to centralized exchange interfaces, which still account for the vast majority of retail transaction volume. Decentralized exchanges like ZilSwap continue to operate, but liquidity remains limited compared to mainstream centralized exchanges. The incident is unlikely to trigger a protocol level downgrade, but will test how the Zilliqa community and its remaining validators respond to a reputation blow.

At the same time, developer activity on Zilliqa has weakened compared to the competitive chain. According to recent data, networks such as Ethereum, Solana and BNB Chain dominate developer activity. For a chain that once positioned itself as a high-throughput alternative, the double whammy of security shocks and shrinking developer footprints has put it in a precarious position.

What happens next?

Zilliqa's investigation is likely to focus on whether the signature process of cold wallets was compromised, whether the multi-signature threshold was bypassed, or whether the physical medium on which the key was held was subject to unauthorized access. Until the investigation report is released, the exchange will keep the recharge channel closed, effectively isolating ZIL in its hot and cold wallets. This quarantine may last for days or weeks, depending on the complexity of the forensic work and whether the partner exchange is regulated in multiple jurisdictions.

The main risk for traders is not a mass sell-off of stolen ZIL-the centralized platform is now blocked-but the pressure of uncertainty. When investigations reveal systemic flaws, affected assets may be traded at discounts below the overall market trend. Currently, ZIL holders are waiting for the truth about the theft that should not have occurred: a cold wallet was breached without even knowing the name of the partner.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP