Zilliqa’s opaque cold-wallet breach reignites exchange disclosure debate
Zilliqa halted ZIL transfers after a partner exchange's cold wallet was compromised, with the sum stolen and exchange involved still undisclosed.

Zilliqa has instructed exchanges to suspend deposits and withdrawals of its ZIL token after a cold wallet belonging to an unnamed exchange partner was compromised, an incident that has left the affected platform, the sum lost and the method of intrusion undisclosed more than a day after the network first flagged the breach.
The layer-1 blockchain project confirmed on 20 July that tokens had been taken from the wallet and said it had launched a joint investigation with the affected partner. In a statement posted to its official channels, Zilliqa said: “We understand the community will have questions. We will share further updates as soon as we have verified information.”
The framing points to a breach at an exchange-side custodian rather than a compromise of the Zilliqa protocol itself, according to crypto.news. Zilliqa has not named the exchange involved, quantified the loss, or offered any technical account of how the attacker gained access, leaving the market to price in uncertainty rather than confirmed detail.
Trading platforms move to contain exposure
Bitget separately announced it would suspend ZIL deposits and withdrawals from 18:15 UTC+8 on 20 July, attributing the pause to “wallet maintenance” without publicly tying the move to Zilliqa’s disclosure. The exchange gave no timeline for reopening the token for transfers.
Such restrictions do not halt activity on the Zilliqa chain itself, where onchain transfers between addresses continue as normal. Rather, they prevent users of participating platforms from moving ZIL onto or off exchanges until operators complete internal checks or receive further guidance from the project team, a distinction that matters for anyone assessing whether the underlying network — as opposed to a custodial intermediary — has been compromised.
ZIL fell by roughly 9% in the 24 hours following the disclosure, changing hands near $0.00254, according to CoinGecko data cited by crypto.news. The decline reflects the standard market response to unresolved custody incidents, where the absence of a confirmed loss figure tends to depress sentiment as much as a disclosed one would.
A recurring weak point in exchange custody
Cold wallets are designed to keep private keys isolated from internet-connected systems and are the default standard for exchanges safeguarding large token balances. Yet the practice does not eliminate every point of failure: signing devices, key-access procedures and internal operational controls remain potential weaknesses even when funds are held offline.
The most consequential precedent remains Bybit’s loss of roughly $1.4 billion in February 2025, when attackers compromised a cold wallet during a routine transfer, an episode that intensified scrutiny of how exchanges manage key custody and staff access. The Zilliqa incident, while apparently smaller in scale based on available information, revives the same underlying question for regulators and institutional counterparties assessing exchange risk: whether cold storage protocols marketed as a security guarantee are being audited with sufficient rigour.
For now, Zilliqa’s silence on the identity of the compromised exchange and the size of the theft leaves both retail holders and larger counterparties without the information typically expected under emerging disclosure norms for digital-asset custodians. Further clarity is likely to depend on whether the unnamed exchange partner issues its own statement, or whether pressure from token holders forces Zilliqa to name it.
Read more: South Korea opens sanctions case against Upbit owner over $30m hack


