HomeAll NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Zilliqa Ledger app vulnerability allows private key recovery

Created at 22 Jul · 12:06 PM1 source↑ Market-relevant
IN SHORT

Zilliqa has warned of a vulnerability in its Ledger app that could allow attackers to reconstruct private keys using on-chain data. The issue affects users who signed at least five native Zilliqa transactions. The ZIL token has fallen 17% in the past week.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

5native Zilliqa transactions signed
1.5%ZIL token 24-hour price change
17%ZIL token weekly price change
$0.0024ZIL token price at publication

Who's Involved

Zilliqa
Layer-1 blockchain network warning of app vulnerability
Ledger
Hardware wallet provider coordinating on app fix

↳ Why This Matters

This vulnerability poses a significant risk to Zilliqa users who rely on Ledger devices for security, potentially leading to the loss of their digital assets if private keys are compromised.

Key facts

  • A vulnerability in the Zilliqa Ledger app allows attackers to reconstruct private keys.
  • Attackers can use publicly available on-chain data to exploit the vulnerability.
  • Users who signed at least five native Zilliqa transactions are considered compromised.
  • Zilliqa previously paused ZIL deposits and withdrawals due to a separate security incident.
  • An undisclosed amount of ZIL was stolen from a cold wallet.

Layer-1 blockchain network Zilliqa has issued a warning regarding a security vulnerability within its Ledger app, which could enable attackers to reconstruct users' private keys by leveraging publicly accessible on-chain data. The vulnerability stems from the generation of signatures with predictably weakened ephemeral nonces, according to Zilliqa's statement on X. Protective measures have been implemented to mitigate further losses, and a remediation plan is currently being finalized. Users who have conducted at least five native Zilliqa transactions using a Ledger device are identified as potentially compromised and are advised to await further instructions. This alert follows Zilliqa's announcement on Monday, which prompted exchanges to temporarily halt Zilliqa (ZIL) deposits and withdrawals after a separate security incident led to the theft of an unspecified quantity of ZIL from a cold wallet. Zilliqa plans to release a corrected version of the app in collaboration with Ledger, and users transacting ZIL via EVM-compatible tools remain unaffected. The ZIL token experienced a 1.5% decline in the preceding 24 hours and a 17% drop over the past week, trading above $0.0024 at the time of publication.

Frequently asked questions

A vulnerability in the Zilliqa Ledger app allows attackers to reconstruct private keys using publicly available on-chain data by exploiting weakened ephemeral nonces in transaction signatures.

Users who have signed at least five native Zilliqa transactions with a Ledger device are considered compromised.

Users are advised to await further guidance from Zilliqa before taking any action.

Exchanges temporarily paused ZIL deposits and withdrawals due to a separate security incident where an undisclosed amount of ZIL was stolen from a cold wallet.

What Happens Next

01Zilliqa will publish a corrected version of the app in coordination with Ledger.
02Users will receive further guidance on actions to take.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Zilliqa identified a security vulnerability in its Ledger app.
The vulnerability allows attackers to reconstruct private keys using on-chain data.
Zilliqa asked exchanges to pause ZIL deposits and withdrawals.
An undisclosed amount of ZIL was stolen from a cold wallet.
Protective measures are in place to prevent further losses.
A coordinated remediation plan is being finalized.
Users who signed at least five native Zilliqa transactions are considered compromised.
Zilliqa will publish a corrected app version with Ledger.

Sources

T1
Zilliqa Ledger app vulnerability lets attackers recover signer’s private keysA security vulnerability in the Zilliqa Ledger app is enabling attackers to reconstruct private keys using publicly available onchain data.Cointelegraph

Related Stories

SecondFi to wind down after $2.6M ADA theft linked to wallet flaw
22 Jul · 9:56 AM
Balance Coin Crashes 99% After $915K Exploit
22 Jul · 3:31 AM
Midnight token rebounds 19% after Wanchain bridge hack, Hoskinson calls for ZK revamp
22 Jul · 11:56 AM
Galaxy Digital Funds $5 Million Initiative for Quantum-Resistant Bitcoin
21 Jul · 1:00 PM
Crypto institutions prioritize operational security over audits: Hacken
22 Jul · 12:16 PM