
Zilliqa cold wallet hack prompts exchanges to pause ZIL deposits and withdrawals as investigators assess the breach and stolen funds.
Author: Kritika Gupta
20th July 2026- Zilliqa disclosed a security incident when the team said attackers stole ZIL from a cold wallet hack held by one of its exchange partners. Zilliqa shared the news at 10:17 UTC and asked every exchange to pause ZIL deposits and withdrawals. So far, it has not named the exchange or the amount lost.
High Signal Summary For A Quick Glance
TotalWorld
@TotalWorldApps
@zilliqa ZIL is fairly safe but cold wallet best practices need tightening up across the board fr
We have been made aware of a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet. The incident is under active investigation, and we are working with the relevant parties to establish the root cause and full scope. As a
11:20 AM·Jul 20, 2026
Helios Hyperion
@HeliosHyperion3
@zilliqa Damn no wonder i tried to do some arbitrage with plunder but shit didnt make on time . Fk the thieves!
We have been made aware of a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet. The incident is under active investigation, and we are working with the relevant parties to establish the root cause and full scope. As a
10:36 AM·Jul 20, 2026
キャンセル
@JunkHealth
@zilliqa It has finally graduated from an ignored crypto to a stolen crypto. Congratulations. My condolences to those who were affected.
We have been made aware of a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet. The incident is under active investigation, and we are working with the relevant parties to establish the root cause and full scope. As a
10:22 AM·Jul 20, 2026
High attention and emotional sentiment detected.
The Zilliqa cold wallet hack now sits under active investigation. According to the team, it is working with the affected parties to pin down the root cause and the full scope. A short follow-up minutes later confirmed only that the review continues.
Zilliqa posted the disclosure from its official account at 10:17:26 UTC. The statement said the team had learned of a breach at an exchange partner. In that breach, ZIL left a cold wallet.
The project framed the theft as a partner problem, not a flaw in the Zilliqa network itself. In other words, the chain kept running normally while the custody breach played out off-chain.
Then, at 10:23:39 UTC, the same account added a brief line. It read: “Investigations are ongoing. More updates to follow when available.”
As a precaution, Zilliqa notified all exchanges and asked them to freeze ZIL deposits and withdrawals. The goal is simple. A pause makes it harder for the attacker to move or sell the stolen funds through centralized venues.
A freeze also buys time for investigators. Once deposits stop, the thief cannot easily convert ZIL into other assets or cash out at scale. So the request works as a containment step, not a fix.
So far, no exchange has publicly confirmed a halt. Compliance with the request therefore remains unverified in primary sources. Major ZIL venues include Binance, KuCoin, Bitget, and Gate, though none has been linked to the breach.
Key milestones in the Zilliqa cold wallet incident
ZIL was allegedly stolen from an unnamed exchange partner’s cold wallet.
Zilliqa asks exchanges to temporarily pause ZIL deposits and withdrawals.
Zilliqa and the relevant parties are assessing the root cause and full scope.
A verified incident report may identify the breach method, exchange and stolen amount.
The affected parties may announce whether impacted users qualify for compensation.
Here is the core of what Zilliqa told the community, quoted directly from its official post.
We have been made aware of a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet. As a precaution, all exchanges have been notified and asked to temporarily pause ZIL deposits and withdrawals. Please rely only on official Zilliqa channels for updates.
The message urged holders to trust official channels only. Scam accounts often exploit these moments with fake recovery links, so caution matters right now.
The distinction here is important. A protocol breach would threaten the Zilliqa blockchain and every wallet on it. A custody breach hits one operator that holds ZIL for its users.
Zilliqa’s wording points to the second case. As a result, the chain and self-custodied holders appear unaffected, though the team has not spelled out the impact on the exchange’s own customers.
A cold wallet keeps private keys offline, usually on air-gapped hardware or specialized signing devices. Exchanges store the bulk of customer assets this way. Then they move only small amounts to hot wallets for daily liquidity.
Because the keys stay offline, draining a true cold wallet is hard. Typically, it takes insider access, a compromised signing ceremony, or a supply-chain attack on the hardware. Social engineering of the signers is another route.
Once an attacker controls enough keys or multisig approvals, the outbound transfers look legitimate on-chain. As a result, the theft can clear before anyone spots it.
Plenty about the Zilliqa cold wallet hack stays unclear. The team has not disclosed the exchange, the ZIL amount, or the dollar value. The exact time of the theft is also unknown, since only the disclosure timestamp is confirmed.
Beyond that, no transaction hashes, compromised addresses, or fund-tracing trails have surfaced. So on-chain analysts cannot yet verify the scale. The root cause, whether insider, error, or supply chain, is still open.
Meanwhile, some traders noted that ZIL slipped around 7% near the disclosure window. However, that figure is not independently confirmed against major price trackers. None of this is financial advice.
This is not Zilliqa’s first brush with a security scare. In February 2025, an X-Bridge flaw allowed unauthorized minting of zETH and zBNB, which hit a ZilSwap pool. The team then suspended operations, offered bounties, and later compensated affected users.
Earlier, in 2020, a staking-contract bug briefly halted reward distribution. User funds stayed safe that time. For context, Zilliqa launched in 2017 and pioneered sharding before its recent Zilliqa 2.0 upgrade.
On X, the early mood mixes calm with pointed questions. Several holders asked why a cold wallet could drain without insider help. Others pushed for transparency on the exchange name and the amount.
The Block and Wu Blockchain both ran short summaries, each noting the missing details. For now, Zilliqa has promised further updates once it verifies the facts.
Next, watch the official Zilliqa account for a named exchange, a confirmed figure, or on-chain evidence. Until the Zilliqa cold wallet hack is fully mapped, treat unverified numbers with caution and rely only on primary channels.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
notnullOSX Malware Targets Mac Users With Crypto Wallets
Ostium Vault Exploit Drains $18M in USDC on Arbitrum
EMURGO Confirms SecondFi Hack Leading Cardano Asset-Recovery Push
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
notnullOSX Malware Targets Mac Users With Crypto Wallets
Ostium Vault Exploit Drains $18M in USDC on Arbitrum
EMURGO Confirms SecondFi Hack Leading Cardano Asset-Recovery Push