Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Zilliqa halts native transactions over bug in its Ledger app dating to 2019

Zilliqa halts native transactions over bug in its Ledger app dating to 2019

The BlockThe Block2026/07/22 12:42
By:The Block

Zilliqa has suspended native ZIL transactions after uncovering a critical vulnerability in its Ledger application that has existed since 2019, making private keys used for affected transactions recoverable from publicly available onchain signatures.

In a statement posted to X on Wednesday, the Zilliqa team said the vulnerability affects the generation of Schnorr signatures for native Zilliqa transactions. The bug causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key using publicly available onchain data.

According to the statement, the team observed onchain activity consistent with active exploitation on July 19 before isolating the root cause on July 21. It attributed the issue to incorrect handling of cryptographic nonce data, where the signing routine copied the wrong 32 bytes from a 40-byte value, leaving the most significant 64 bits of each nonce fixed at zero. 

That reduction in randomness allowed private keys to be reconstructed from approximately five or more affected signatures using publicly available onchain data, the team said. 

Per the statement, protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalized. A corrected version of the Zilliqa Ledger app is being prepared in coordination with Ledger, with release details to be announced separately. 

Meanwhile, users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action, the team said. It added that users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected by the vulnerability.

The team also credited KuCoin for helping identify the root cause of the app's nonce generation flaw, recovering affected private keys from publicly available onchain signatures, and confirming that the vulnerability was being actively exploited. 

Zilliqa said the exchange's reporting and cooperation enabled the implementation of protective measures while the remediation plan was being developed.

Zilliqa's ZIL (ZIL) token traded down 4.8% over the past 24 hours at $0.0024.


0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Meta shocks Wall Street by hiring MongoDB CEO and makes a high-profile entry into enterprise AI business

Meta has established an enterprise AI division called "Meta Enterprise Platform," which Mark Zuckerberg described as "the next important pillar." MongoDB CEO CJ Desai has been recruited to lead it. Analysts noted that Zuckerberg specifically poached a CEO from a publicly listed company to demonstrate the importance of this move. Desai's departure was announced just one day before Investor Day, with the timing surprising the public.

华尔街见闻•2026/09/29 00:51

AstraZeneca invests $2 billion in Summit, optimistic about Akeso's Ivose

This 18.6% premium subscription is not only a substantial endorsement, but both parties will also deeply collaborate on the joint development of combination therapies such as ADCs. The core of this deal is Akeso's Ivonescimab—the world’s first PD-1/VEGF bispecific antibody, and so far the only drug to have surpassed "K-drug" in head-to-head trials on both PFS and OS endpoints. The median OS reached 30.8 months, compared to 22.6 months for "K-drug", representing a 27% reduction in risk of death.

华尔街见闻•2026/09/29 00:26