Where We Stand: Migration Progress, the Path to Compensation, and Getting Back to Building
Six weeks ago we disabled legacy transactions on Zilliqa to stop the exploitation of a signing flaw in the Zilliqa Ledger app. Since then, our focus - and a good part of the wider ecosystem - has been on containment, root-cause analysis, and building the path back for everyone affected. On September 2nd we took the first concrete step on that path: a hard fork that migrated ZIL balances for a first batch of exchanges from Legacy addresses to Zilliqa EVM.
This update is a summary of where things stand across the three workstreams we know the community is watching most closely - exchange migration, retail (self-custody) migration, and compensation for affected holders - and a word on the roadmap we haven't stopped working on in the background.
If you're catching up, the full incident record remains at the Ledger Incident Hub, including the Post-mortem and the Exchange FAQ.
Exchange migration: first batch done, second batch mid-September
The September 2nd hard fork reassigned balances at the protocol level for a first group of ten exchange partners, moving their legacy Schnorr-based balances directly to their Zilliqa EVM addresses. No user action was required for this step, and exchanges are working through their own testing before restoring ZIL deposits and withdrawals on their platforms.
This was explicitly a first batch, not the finish line. We're still collecting and verifying address mappings from additional exchange partners, and we're planning a second hard fork for mid-September to migrate this next group. If you hold ZIL on an exchange that wasn't included on September 2nd, that doesn't mean you've been forgotten - it means your exchange's submission is still in the pipeline. We'll confirm the exchanges and the exact date as soon as the mappings are locked.
Retail migration: the self-guided tool is in final stages
The much larger group - legacy wallet holders who self-custody their ZIL - has understandably been the hardest to keep waiting. We can now say the self-guided migration tool is in its final stages of development and is on track for release in mid-September.
This tool is built on zero-knowledge proofs, which means holders will be able to migrate their stuck legacy ZIL balances to Zilliqa EVM addresses themselves, without ever exposing a seed phrase or private key to us or to anyone else. It's designed to be something you run yourself, on your own schedule, once it's live.
Because a ZK-based migration of this kind depends on a trusted setup, we're finalizing the group of participants who will take part in that setup ceremony. We can already confirm it will include Zilliqa, LTIN, an independent web3 security audit firm, an exchange partner, and community participants - reflecting the same principle we've tried to apply throughout this process: no single party should be able to act alone on something this sensitive. We'll publish the full, finalized list of participants and the ceremony details before the tool goes live.
Compensation: what we're proposing, and why we're putting it to a vote
We know this is the question that matters most, and we're not going to dance around it: how are the stolen funds addressed for the people who lost them?
The honest answer is that legal recovery of stolen assets through cross-border tracing and enforcement is a real avenue, but it is also, realistically, a slow and uncertain one - anyone who tells you otherwise about a process like this isn't being straight with you. We don't think it's fair to make affected holders wait on that outcome alone.
So in parallel with the legal process, we are preparing a community vote on an adjustment to ZIL tokenomics that would include a proposed mint of new tokens specifically to compensate impacted users. This is deliberately a decision we're putting to the community rather than making unilaterally, because it changes token supply and affects every ZIL holder, not only those directly impacted. The full proposal - including the mechanics, amounts, and eligibility - will be published on https://gov.zilliqa.com/ as soon as it's ready.
Depending on how that vote goes, a mint-based compensation could move considerably faster than the legal process, without foreclosing continued efforts to recover the stolen funds through legitimate legal channels. We'd rather give the community a real choice on speed versus other tradeoffs than quietly wait years for a court process to conclude.
Getting back to the roadmap
Earlier this year we set out a new direction for Zilliqa: a mediation layer for institutional finance, built around compliance checks that happen before settlement rather than after. That roadmap hasn't changed, and neither has our conviction in it.
What has changed is where our attention has been. For the past six weeks, effectively the entire organization has been focused on containing and remediating this incident, and rightly so - that had to come first. But work on the strategic roadmap didn't stop entirely in the background, even while it wasn't the headline. We're not going to announce specific milestones ahead of fully securing and validating them - we'd rather ship something real than talk about something early - but we want to be clear that our commitment to this direction hasn't wavered for a single day.
Our goal is to have the organization's full attention back on executing that roadmap from mid-September, once the second exchange hard fork and the retail migration tool are both live. We'll have more to share on specific progress once we're confident it's ready to stand on its own.
The part worth saying out loud
None of this makes the incident anything other than what it was: a serious failure that cost real people real funds. But it would be dishonest to pretend nothing good came out of the six weeks since.
This forced us to make a decision we'd been circling for a long time and might otherwise have kept deferring: retiring the legacy, non-EVM Zilliqa transaction infrastructure entirely. That legacy stack predated not just Zilliqa 2.0 but the current era of tooling, automation, and increasingly sophisticated exploit techniques altogether, and it had been a growing liability from both a development and a security standpoint for a while. Moving the entire chain to Zilliqa EVM, on a single modern execution environment, is a healthier place for us to build from - and it's one we're glad to be arriving at now rather than after a future, possibly worse, incident forced our hand.
What to watch for next
- Mid-September: second hard fork migrating the next batch of exchanges
- Mid-September: release of the self-guided, zero-knowledge retail migration tool
- Ahead of both: the finalized migration ceremony participant list
- As soon as ready: the compensation and tokenomics proposal on https://gov.zilliqa.com/
We'll keep the Ledger Incident Hub current as each of these lands, and we'll post here again once the second hard fork and the migration tool are both behind us. Thank you for the patience so far - we know it's been asked of you a lot these past six weeks, and we don't take it for granted.
- The Zilliqa Team