Zilliqa has made an address checker live and begun an audit of its migration tool following a security incident affecting users of the blockchain's Ledger hardware wallet integration, the company said in a post on X.

The incident compromised user addresses tied to Zilliqa's Ledger app. Zilliqa did not disclose the total number of affected addresses, the amount of ZIL stolen, or the number of users harmed. The company said it is working with legal authorities and exchange partners to trace the stolen funds but declined to share further details while the investigation is ongoing.

The address checker allows users to verify whether their holdings were compromised. Zilliqa said it will announce a launch date for the migration tool once the audit findings have been reviewed. The tool is designed to help affected users recover or move their assets.

Zilliqa has lined up several exchanges to support the migration process. The company is targeting the end of August for the first batch of exchange migrations, meaning users can begin moving affected assets to new addresses through those platforms within weeks.

MSB Intel

The Ledger integration is a key custody pathway for Zilliqa holders. Hardware wallets like Ledger are used by institutional and retail investors to store cryptocurrency offline, insulating assets from exchange hacks and smart contract exploits. A compromise of the integration layer itself is rare and typically requires either a breach of the app's code repository, a supply chain attack on Ledger's infrastructure, or a flaw in how the app manages user address derivation.

Zilliqa announced the incident after the company had already begun recovery efforts behind the scenes. The address checker and staged migration timeline arrive weeks after the breach occurred. The end-of-August deadline for first-batch exchange migrations is aggressive; most security incidents of this scope take months to resolve fully.

The company has not released a detailed postmortem explaining what caused the breach or how many transactions were executed from compromised addresses. Exchange support and a multi-week recovery window are faster than typical for wallet-level incidents, which often stall at the technical or legal discovery phase for longer.