Zilliqa halts native transactions over bug in its Ledger app dating to 2019
Zilliqa has suspended native ZIL transactions after uncovering a critical vulnerability in its Ledger application that has existed since 2019, making private keys used for affected transactions recoverable from publicly available onchain signatures.
In a statement posted to X on Wednesday, the Zilliqa team said the vulnerability affects the generation of Schnorr signatures for native Zilliqa transactions. The bug causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key using publicly available onchain data.
According to the statement, the team observed onchain activity consistent with active exploitation on July 19 before isolating the root cause on July 21. It attributed the issue to incorrect handling of cryptographic nonce data, where the signing routine copied the wrong 32 bytes from a 40-byte value, leaving the most significant 64 bits of each nonce fixed at zero.
That reduction in randomness allowed private keys to be reconstructed from approximately five or more affected signatures using publicly available onchain data, the team said.
Per the statement, protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalized. A corrected version of the Zilliqa Ledger app is being prepared in coordination with Ledger, with release details to be announced separately.
Meanwhile, users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action, the team said. It added that users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected by the vulnerability.
The team also credited KuCoin for helping identify the root cause of the app's nonce generation flaw, recovering affected private keys from publicly available onchain signatures, and confirming that the vulnerability was being actively exploited.
Zilliqa said the exchange's reporting and cooperation enabled the implementation of protective measures while the remediation plan was being developed.
Zilliqa's ZIL (ZIL) token traded down 4.8% over the past 24 hours at $0.0024.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Wintermute’s Aggressive Liquidations Trigger Panic: 5 Cryptos Worth Risking Before Buyers Return to the Market

Once the Federal Reserve starts the rate hike cycle, is "three consecutive hikes" a reasonable expectation?
BMO expects consecutive rate hikes in October and December, with a total of three increases potentially wiping out all rate cut gains for 2025. Vanguard believes "three consecutive hikes" is a reasonable starting point, but the actual number could be as high as six. There are historical exceptions: in 1997, the Federal Reserve raised rates only once and took no further action for the following 18 months. Meanwhile, trillion-dollar debt financing by AI giants, private credit exposure in the insurance industry, and the 10-year U.S. Treasury yield approaching 5% are the most dangerous pressure points in this rate hike cycle.
Goldman Sachs Also Changes Its Tune: The Fed Will Raise Interest Rates Next Week!
Goldman Sachs has shifted from predicting a rate hold to betting on a 25 basis point hike next week, stating that this change is not due to particularly bad inflation data—the August CPI was not perfect, but it wasn’t alarming either. The real key is that hawkish comments from Waller have already shaped market expectations: "If the inflation data isn’t perfect, there will be a rate hike." If the Federal Reserve backs down now, its credibility will suffer a serious blow and long-term interest rates could react sharply and immediately.

