Zilliqa Confirms ZIL Stolen From Exchange Partner's Cold Wallet
Zilliqa is scrambling to contain the fallout from a security breach after confirming that ZIL tokens were stolen from a cold wallet controlled by one of its exchange partners, forcing a coordinated freeze on deposits and withdrawals across multiple trading platforms.
The layer-1 blockchain, known for its sharding architecture and its push into real-world asset tokenization, broke the news on X, telling followers it had been made aware of "a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet." The team said the matter is under active investigation and that it is working alongside the affected parties to determine the root cause and the full scope of the loss.
What's Known And What Isn't
True to the pattern seen in most exchange-side breaches, Zilliqa's disclosure was long on caution and short on specifics. The project has not named the exchange partner involved, has not disclosed how much ZIL was taken, and has not said whether the attacker exploited a technical vulnerability, compromised signing keys, or took advantage of an internal process failure. Cold wallets are, by design, kept offline specifically to avoid this category of remote attack, which makes the breach notable regardless of its eventual size.

As a containment measure, Zilliqa asked every exchange handling ZIL to pause deposits and withdrawals temporarily, a step aimed at stopping the attacker from moving or cashing out the stolen tokens through centralized order books before investigators can trace the funds. The network's core blockchain itself is reportedly functioning normally; the incident is being treated as a breach at the partner exchange level rather than a compromise of Zilliqa's protocol.
The uncertainty has weighed on the token in the meantime, with ZIL sliding roughly 7–9% in the hours following the announcement as traders priced in the risk of an unresolved exploit and an extended freeze on transfers.
Part of a Busier Week for Crypto Security
The Zilliqa incident lands in the middle of a cluster of security stories hitting the industry within days of each other. Blockchain investigator ZachXBT separately flagged an undisclosed exploit on the TeleSwap cross-chain bridge, pegging the loss at roughly $735,000 after tracing suspicious outflows and criticizing the project for staying quiet about the attack for nearly a week before it surfaced publicly. Bridge protocols Across and Allbridge were also hit by attackers in the same stretch, pushing total losses across the three platforms past $5.7 million and adding to a running 2026 tally of bridge-related losses that has already climbed past $350 million, according to tracking from industry researchers at Protos.
Taken together, the incidents underline a persistent theme in crypto security this year: attackers are increasingly probing the seams between blockchains and the centralized infrastructure — exchanges, custodians and bridges, that sits on top of them, rather than attacking base-layer protocols directly. Cold storage has long been treated as the gold standard for protecting exchange reserves, but recent history, including last year's roughly $1.46 billion Bybit breach and the WazirX multisig compromise, shows that offline key storage alone doesn't eliminate risk when the surrounding custody process, signing workflow, or partner infrastructure has a weak link.
For now, ZIL holders on affected exchanges are left waiting. Zilliqa has given no timeline for when deposits and withdrawals will resume, and has asked the community to rely only on its official channels for updates rather than unverified chatter as the investigation continues.
5% deposit bonus up to 100 gems

a free Gift Case


EGAMERSW - get 11% Deposit Bonus + Bonus Wheel free spin
EXTRA 10% DEPOSIT BONUS + free 2 spins
3 Free Cases + 100% up to 100 Coins on First Deposit
5 Free Cases, Daily FREE & Welcome Bonuses up to 35%

3 free cases and a 5% bonus added to all cash deposits.

+5% to deposit


Comments