Key facts
- A vulnerability in the Zilliqa Ledger app allows attackers to reconstruct private keys.
- Attackers can use publicly available on-chain data to exploit the vulnerability.
- Users who signed at least five native Zilliqa transactions are considered compromised.
- Zilliqa previously paused ZIL deposits and withdrawals due to a separate security incident.
- An undisclosed amount of ZIL was stolen from a cold wallet.
Layer-1 blockchain network Zilliqa has issued a warning regarding a security vulnerability within its Ledger app, which could enable attackers to reconstruct users' private keys by leveraging publicly accessible on-chain data. The vulnerability stems from the generation of signatures with predictably weakened ephemeral nonces, according to Zilliqa's statement on X. Protective measures have been implemented to mitigate further losses, and a remediation plan is currently being finalized. Users who have conducted at least five native Zilliqa transactions using a Ledger device are identified as potentially compromised and are advised to await further instructions. This alert follows Zilliqa's announcement on Monday, which prompted exchanges to temporarily halt Zilliqa (ZIL) deposits and withdrawals after a separate security incident led to the theft of an unspecified quantity of ZIL from a cold wallet. Zilliqa plans to release a corrected version of the app in collaboration with Ledger, and users transacting ZIL via EVM-compatible tools remain unaffected. The ZIL token experienced a 1.5% decline in the preceding 24 hours and a 17% drop over the past week, trading above $0.0024 at the time of publication.