📈 Get daily crypto insights that make you smarter about your money

Binance Migrates ZIL to Zilliqa EVM as Legacy Network Retires After 683 Million ZIL Ledger Flaw

Binance has confirmed it will migrate ZIL deposits and withdrawals from the legacy Zilliqa network to Zilliqa EVM at a 1:1 ratio, becoming the largest exchange yet to complete the retirement of the blockchain’s original Schnorr-based transaction system after a Ledger application flaw exposed thousands of accounts and led to the theft of at least 683.13 million ZIL.

By Amir Hassan | September 23, 2026

The exchange said in an announcement that ZIL will be moved from legacy Zilliqa mainnet addresses to the Zilliqa EVM network at a one-to-one ratio, with Binance handling the technical process for users who hold the token on its platform. Deposits and withdrawals through the legacy network have been suspended on Binance since August 5 at 01:00 UTC, and once the migration is complete the exchange will open ZIL deposits and withdrawals through Zilliqa EVM without issuing a separate announcement.

Spot trading, margin trading, futures and Binance Earn products involving ZIL will remain available throughout the process, the exchange added.

Why the legacy network is being retired

The migration stems from a vulnerability in Zilliqa’s Ledger application that affected native, non-EVM transactions signed with Ledger hardware devices. According to Zilliqa’s August 20 post-mortem, the application mishandled the random number, or nonce, used in Schnorr signatures: the generated data was incorrectly copied into the signing buffer, leaving the top 64 bits of each nonce fixed at zero. That collapse in randomness meant an attacker who collected several public signatures from the same account could reconstruct its private key.

The defect had been present in every released version of the Zilliqa Ledger application between 2019 and 2026. Zilliqa said the first proven theft occurred on March 4, months before the problem was detected. Suspicious activity picked up in July, and KuCoin notified the project on July 19 after finding unusual outgoing transactions from one of its cold wallets. Zilliqa disabled legacy transactions on July 20 and identified the root cause the following day.

The project later confirmed that at least 683.13 million ZIL was stolen across 66 transactions. A total of 6,772 accounts were identified as exposed and 51 accounts were drained — figures Zilliqa described as minimum confirmed totals, since additional exposed accounts could still be identified.

Crucially, EVM transactions on Zilliqa were never affected, and software wallets using supported SDKs generated nonces correctly. The recovery phrase stored on Ledger devices was also not exposed. But because signatures are stored permanently on-chain, Zilliqa concluded it could not secure private keys that had already leaked signatures — so the legacy transaction system had to go.

A migration carried out in hard-fork batches

Exchange migrations have been executed in batches because each participating platform must provide and verify its EVM wallet addresses before balances can be reassigned at the protocol level. The first exchange migration hard fork took place on September 2, moving balances held in legacy Schnorr-based wallets to EVM addresses supplied by KuCoin, MEXC, OKCoin, Binance US, Bitvavo, Korbit, Indodax, Bitrue, WhiteBIT, CoinSpot and CoinSwitch. Users holding ZIL on those exchanges were not required to take any action.

A second hard fork on September 22 covered CoinEx, HTX, Bitkub, GOPAX, Coinone, OKX, LBank, Crypto.com, Gate, Paribu, CEX.IO and Bitget. Bybit and Bithumb were expected to join a third migration fork, while Binance — which had remained outside the earlier batches — has now confirmed it will drop legacy-network support entirely and route its ZIL infrastructure through Zilliqa EVM.

Self-custody holders get a zero-knowledge route

Exchange customers are not the only holders affected. Zilliqa has built a zero-knowledge-proof migration system for users who hold ZIL in their own legacy wallets, allowing a holder to prove ownership of an old address and move the balance to an EVM address without ever sharing a seed phrase or private key. The audit of the ZKP migration tool has been completed, according to a September update, with internal testing following the security review, and its rollout was targeted for September 22 alongside an escrow contract required for the process.

The project has warned users against attempting to move funds through exposed legacy keys. Once an attacker reconstructs a private key from old signatures, both the legitimate holder and the attacker can sign transactions from the account — which is why legacy transactions were disabled for all holders, including accounts that were never exposed. Stolen balances are being handled separately from the exchange migration forks: Zilliqa is working with exchanges and law enforcement to trace the stolen assets, and its post-mortem said an exchange account used to liquidate part of the stolen funds has been identified and frozen, with the project cooperating with Singapore Police and a law firm on recovery.

The team has also proposed a community vote on tokenomics changes that could include minting tokens to compensate affected holders, with details on eligibility and mechanics to be released alongside the governance proposal.

The verdict: an accelerated end to a dual-stack era

Zilliqa’s move toward EVM infrastructure predates the incident: the network transitioned to Zilliqa 2.0 in June 2025, bringing full Ethereum Virtual Machine compatibility and proof-of-stake consensus after a six-month testing period involving 21 external validators, 7.5 million blocks processed on the proto-mainnet and 15 client upgrades. Legacy transaction support had continued alongside the EVM environment — but the Ledger incident forced a decision the project says it had already been considering, describing the legacy stack as an increasing development and security liability.

For Binance users, the practical impact is minimal: balances migrate automatically and trading continues uninterrupted. For the wider industry, the episode is a reminder that decade-old code paths in hardware wallet integrations can carry dormant, key-exposing defects — and that on-chain signatures are forever. The retirement of the legacy Zilliqa network, painful as it was, converts a slow-motion security liability into a clean, EVM-only production environment.

Market snapshot (CoinGecko, Sept. 23): BTC 85,636 USD, ETH 2,727 USD, SOL 117 USD.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Crypto assets are volatile and readers should do their own research.

10 thoughts on “Binance Migrates ZIL to Zilliqa EVM as Legacy Network Retires After 683 Million ZIL Ledger Flaw”

  1. 683 million ZIL gone because of a Ledger app bug and the fix is just… retire the network. brutal for anyone who kept native ZIL on a hardware wallet

    1. they did publish the migration path tho, 1:1 swap handled by binance. real pain is for self custody folks who missed the august 5 cutoff

  2. 1:1 migration is the least they could do. still wild that spot and futures kept trading the whole time the legacy chain was basically compromised

  3. top 64 bits of the schnorr nonce fixed at zero, in every ledger app release since 2019. seven years of signatures sitting there ready for private key reconstruction. brutal

    1. KuCoin catching it via unusual outflows from a cold wallet first is darkly funny. The project itself missed months of thefts starting March 4.

      1. kucoin flagged the cold wallet outflows before zilliqa itself noticed anything. says everything about how thin native chain monitoring had gotten by 2026

  4. 683 million ZIL gone and the grand fix is migrate everything to an EVM. one bad memcpy in a hardware wallet app killed an entire transaction system. anyone still holding ZIL through this deserves a medal

    1. It is not the whole fix though. Zilliqa EVM inherits the ERC-20 tooling and audit surface people actually test. Schnorr support outside ZIL was basically three devs and a Ledger app.

  5. march 4 first theft, august 5 deposits frozen, sept 23 full migrate. seven months of known-broken nonces on the old chain. binance doing 1:1 is fine but the timeline is the scary part

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,460.00-0.6%ETH$2,722.15-1.0%SOL$116.93-0.3%BNB$779.72-0.9%XRP$1.57+1.8%ADA$0.2503+1.1%DOGE$0.0996+0.8%DOT$1.16-0.9%AVAX$10.75-0.6%LINK$12.73-1.7%UNI$9.70+4.8%ATOM$1.82+3.7%LTC$62.20+2.5%ARB$0.2351+7.1%NEAR$4.73+2.7%FIL$1.03+2.2%SUI$1.01-0.4%BTC$85,460.00-0.6%ETH$2,722.15-1.0%SOL$116.93-0.3%BNB$779.72-0.9%XRP$1.57+1.8%ADA$0.2503+1.1%DOGE$0.0996+0.8%DOT$1.16-0.9%AVAX$10.75-0.6%LINK$12.73-1.7%UNI$9.70+4.8%ATOM$1.82+3.7%LTC$62.20+2.5%ARB$0.2351+7.1%NEAR$4.73+2.7%FIL$1.03+2.2%SUI$1.01-0.4%
Scroll to Top