
Zilliqa's X account reported that an undisclosed amount of ZIL had been stolen from the cold wallet of one of Zilliqa's exchange partners. Later, the same account announced that the incident was linked to a technical issue affecting transaction signing in an outdated version of the wallet.
As far as I can recall, this is probably the first time a technical problem has been cited as the cause of theft from a cold wallet. It will be very useful to learn the details once they come out. As a rule, hacks and exploits tend to happen only when a wallet is "hot" - meaning its private keys could, at least in theory, be accessed by other devices.
While we wait for more details, I want to point out another side of what happened. The Zilliqa team asked exchanges to temporarily suspend ZIL deposits and withdrawals in order to prevent the stolen tokens from being moved or sold.
But exchanges are far from the only way to offload stolen crypto. When someone creates a swap order on rabbit.io, our automated system scans the market for the best available rate - and right now, we can still see plenty of options for swapping ZIL. Exchanges cutting off deposits and withdrawals will not change that one bit. What it will do is hurt ordinary users who have nothing to do with the theft.
What is your take - should exchanges go along with Zilliqa's request and suspend ZIL deposits and withdrawals? Or should their first priority be protecting the interests of legitimate customers?