Zilliqa Ledger Bug Lets Attackers Snatch Private Keys From Weak Signatures 🔐
Layer-1 blockchain network Zilliqa disclosed Wednesday that a vulnerability in the Zilliqa Ledger app could allow attackers to recover users' private keys using publicly available onchain data. "The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key," Zilliqa said in a Wednesday X post.
Zilliqa stated that protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized. The network added that a corrected version of the app will be published in coordination with Ledger. Users who transacted ZIL through EVM-compatible tooling were not affected, according to the network.
Any user who signed at least five native Zilliqa transactions with a Ledger device is considered compromised and has been advised to await further guidance before taking any action.
The disclosure follows a Monday request from Zilliqa asking exchanges to temporarily pause ZIL deposits and withdrawals after the project identified a security vulnerability that resulted in the theft of an undisclosed amount of ZIL from a cold wallet.
The ZIL token fell 1.5% in the past 24 hours and 17% over the past week, trading above $0.0024 at publication, according to CoinMarketCap.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.