PANews, July 22: According to a Zilliqa announcement, a critical nonce vulnerability has been identified in the Zilliqa Ledger app that affects Schnorr signatures for native (non-EVM) ZIL transactions, causing the 64 most significant bits of the generated temporary nonce to always be zero. Attackers can recover private keys within seconds using approximately five on-chain transaction signatures. This flaw has existed in all versions of the Zilliqa Ledger app since 2019. Native transactions have been suspended, affected keys must be discarded, and the risk cannot be fully mitigated through ordinary transfers alone.
Zilliqa Discovers Critical Random Number Vulnerability in Ledger App Affecting ZIL Private Keys
PANewsShare
Zilliqa has discovered a critical flaw in its Ledger app related to Schnorr signatures for native ZIL transactions, raising concerns under CFT and MiCA compliance. The vulnerability, present since 2019, enables attackers to recover private keys using only five signatures. Native transactions have been paused, and affected keys must be discarded. MiCA’s regulatory framework may require additional actions due to the impact on key security.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.