Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
Zilliqa halts native transactions over bug in its Ledger app dating to 2019

Zilliqa halts native transactions over bug in its Ledger app dating to 2019

The BlockThe Block2026/07/22 12:42
By:The Block

Zilliqa has suspended native ZIL transactions after uncovering a critical vulnerability in its Ledger application that has existed since 2019, making private keys used for affected transactions recoverable from publicly available onchain signatures.

In a statement posted to X on Wednesday, the Zilliqa team said the vulnerability affects the generation of Schnorr signatures for native Zilliqa transactions. The bug causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key using publicly available onchain data.

According to the statement, the team observed onchain activity consistent with active exploitation on July 19 before isolating the root cause on July 21. It attributed the issue to incorrect handling of cryptographic nonce data, where the signing routine copied the wrong 32 bytes from a 40-byte value, leaving the most significant 64 bits of each nonce fixed at zero. 

That reduction in randomness allowed private keys to be reconstructed from approximately five or more affected signatures using publicly available onchain data, the team said. 

Per the statement, protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalized. A corrected version of the Zilliqa Ledger app is being prepared in coordination with Ledger, with release details to be announced separately. 

Meanwhile, users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action, the team said. It added that users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected by the vulnerability.

The team also credited KuCoin for helping identify the root cause of the app's nonce generation flaw, recovering affected private keys from publicly available onchain signatures, and confirming that the vulnerability was being actively exploited. 

Zilliqa said the exchange's reporting and cooperation enabled the implementation of protective measures while the remediation plan was being developed.

Zilliqa's ZIL (ZIL) token traded down 4.8% over the past 24 hours at $0.0024.


0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

The data center arms race extends to power infrastructure as Amazon signs a $8 billion, seven-year strategic agreement with Generac

Amazon has signed a generator supply agreement with Generac worth up to $8 billion over seven years. The first batch of orders, valued at $2.4 billion, will be delivered between 2027 and 2028, and long-term procurement will be further secured through warrants. Analysts predict that this agreement will enhance the certainty of Generac’s future earnings and demonstrates that the expansion of AI data centers is extending demand from chips and servers to power generation equipment and other electrical infrastructure.

华尔街见闻2026/09/17 13:41

The Bank of England keeps interest rates unchanged; balance sheet reduction is more than expected

The Bank of England announced on Thursday that it will keep its benchmark interest rate unchanged at 3.75%, in line with general market expectations.

智通财经2026/09/17 12:51