ME News reports that on July 22 (UTC+8), Zilliqa disclosed a critical vulnerability in its Ledger app affecting Schnorr signature generation for native (non-EVM) Zilliqa transactions. The vulnerability exists in all versions of the Zilliqa Ledger app released between 2019 and 2026. On July 19, on-chain evidence of suspected active exploitation was detected, and the root cause was confirmed on July 21. The flaw allows attackers to predict the temporary nonce used during signature generation, enabling them to reconstruct the signer’s private key using only publicly available on-chain data. Zilliqa advises users who have previously signed native Zilliqa transactions with Ledger devices to await official guidance and refrain from taking any independent action. The root cause lies in the signature program copying an incorrect byte range when writing the nonce to the buffer, resulting in the highest 64 bits of every generated nonce being fixed at zero, severely reducing entropy. With five or more affected signatures, attackers can recover the private key within seconds using lattice reduction. Since the affected transactions are permanently recorded on-chain, updating the signature app cannot reverse this risk—the associated private keys must be discarded. Native transactions have been temporarily suspended to prevent further losses, and a coordinated remediation plan is currently being finalized. EVM transactions and SDKs such as zilliqa-js, gozilliqa-sdk, and pyzil are unaffected. (Source: Foresight News)
Zilliqa Ledger App Vulnerability Exposes Native Transaction Signatures
KuCoinFlashShare
Zilliqa has confirmed a critical flaw in its Ledger app affecting digital signatures for native (non-EVM) transactions. The vulnerability, present since 2019, enables attackers to predict nonces in Schnorr signatures due to a buffer copy error. This flaw zeroes out the top 64 bits, reducing entropy and allowing private key recovery after as few as five transactions. Native transactions have been temporarily paused while a fix is finalized. EVM transactions and SDKs are unaffected.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.