Timing
The first exchange-migration recovery hard fork is scheduled at block 34,844,968, estimated around 12:58 UTC on September 2. At report time, that target is still in the future. CEXVia therefore describes it as Scheduled / Pending.
Root cause
Zilliqa’s official post-mortem says the legacy Ledger app generated Schnorr nonces correctly but copied them into the signing buffer incorrectly, retaining eight bytes of zero padding and discarding eight bytes of entropy.
The top 64 bits were therefore fixed at zero, leaving 192 effective random bits. That bias leaked enough information for private-key recovery from multiple public signatures.
Proven scope
Zilliqa reports 683,130,969.66 ZIL of proven theft, 6,772 known exposed accounts, 51 drained accounts, and says 73.9% of attributable legacy addresses were safe by construction.
The proven-theft number is cryptographically established, not merely an on-chain behavioral estimate.
What the fork does
The first migration moves legitimate exchange-controlled balances from legacy Schnorr addresses to verified Zilliqa EVM addresses.
The first batch includes KuCoin, MEXC, OKCoin, Binance US, Bitvavo, DigitalX/Korbit, Indodax, Bitrue, WhiteBIT, CoinSpot and CoinSwitch. Other exchanges are expected in later batches.
Stolen balances and self-custody
Zilliqa says balances identified as stolen will not be restored through the fork.
The first batch focuses on exchange custody. Legacy self-custody holders remain part of the broader universal migration/recovery plan and should avoid unofficial migration tools.
Evidence Status
Confirmed: root cause, proven theft, exposure counts, target block, first-batch exchange list, stolen-balance exclusion.
Developing: final theft ceiling, recovery of stolen ZIL, later exchange batches, self-custody migration timeline.
Risk Assessment
Critical. A protocol-level recovery fork does not reduce the severity of a private-key exposure event that produced proven theft of hundreds of millions of ZIL.
What to Watch Next
Fork activation; exchange-balance migration; CEX deposit/withdrawal reopenings; later batches; self-custody tooling; recovery-tool audit; asset tracing; phishing.
FAQ
Has the hard fork already happened?
Not at report time. It is scheduled for block 34,844,968.
How much ZIL was stolen?
Zilliqa reports 683,130,969.66 ZIL of proven theft.
Were all legacy wallets vulnerable?
No. Zilliqa says most attributable legacy addresses were safe by construction.
Will attacker balances migrate?
No. Identified stolen balances are excluded.