Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

Дата публикации: 24-07-2026 16:40:53

Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the same private key may provide enough information to reconstruct that key, creating a recovery problem that an ordinary transfer cannot safely solve. The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, according to […]
The post A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds appeared first on CryptoSlate.


Основное содержимое страницы с новостью.

Acid-green editorial collage showing five signature fragments beside a shattered padlock revealing a glowing Zilliqa-shaped private key, with a chained transaction gate in the background.Image by CryptoSlate

The network has suspended native transactions while it develops a migration process designed to stop attackers with reconstructed private keys from front-running affected users.

Liam 'Akiba' Wright

Editor-in-Chief CryptoSlate

  1. Zilliqa suspended native transactions after a Ledger app flaw exposed private keys from roughly five signatures.
  2. Biased nonces let attackers reconstruct keys within seconds; past on-chain signatures cannot be fixed by updating the app.
  3. Ordinary transfers could be front-run, so affected users must wait for Zilliqa’s coordinated migration plan.

Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the same private key may provide enough information to reconstruct that key, creating a recovery problem that an ordinary transfer cannot safely solve.

The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, according to the network’s security disclosure. Zilliqa said every version of the app released between 2019 and 2026 contained the flaw.

Zilliqa said it detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. The disclosure did not identify affected addresses or quantify any losses.

Public signatures can expose the private key

The flaw occurred while the Ledger app generated the ephemeral nonce required for each native Zilliqa signature. The signing routine generated 40 bytes of randomness and reduced the result modulo the secp256k1 curve order, but then copied the wrong 32-byte range into the nonce buffer.

That operation retained eight zero-padding bytes while discarding eight bytes of actual entropy, fixing the nonce’s highest 64 bits at zero and leaving each value below 2192.

Zilliqa said an attacker can combine approximately five affected signatures produced by the same private key and use lattice-reduction techniques to reconstruct that key within seconds on commodity hardware.

Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should therefore be considered compromised, according to Zilliqa. The weakened signatures remain permanently available on-chain, so updating the app cannot remove the information already exposed. Affected private keys must ultimately be retired.

Zilliqa credited KuCoin with reporting the incident and helping confirm the vulnerability. According to the disclosure, the exchange recovered affected private keys using publicly available signatures and assisted in tracing the problem to the app’s nonce-generation code.

A normal rescue transfer could be front-run

Moving assets to a new address once native transactions resume carries another risk. An attacker who has already reconstructed the private key can also sign a valid transaction and attempt to front-run the legitimate holder’s transfer.

This leaves Zilliqa balancing two requirements before reopening native activity: allowing legitimate users to migrate their assets while preventing attackers with the same signing authority from winning the transaction race.

The network said it was finalizing a coordinated remediation plan and advised anyone who has signed native Zilliqa transactions with a Ledger device to await official instructions before taking action.

Zilliqa suspended native, non-EVM transactions as a protective measure after identifying the vulnerability. The project said the pause halted further draining of affected accounts.

At publication time, Zilliqa had not announced a reopening date or published its final migration procedure through its official channels.

A corrected version of the Ledger app is being prepared in coordination with Ledger and will restore full-width nonce generation. The update can prevent future signatures from exposing the same information, but it cannot secure keys compromised by signatures already recorded on-chain. Zilliqa said release details would be announced separately.

EVM and official SDK signing paths are unaffected

The disclosure does not describe a compromise of Ledger hardware generally. Zilliqa attributed the vulnerability to its Ledger app’s implementation of native transaction signing.

Zilliqa said EVM transactions are unaffected. The nonce-generation paths used by its official zilliqa-js, gozilliqa-sdk, and pyzil software development kits also fall outside the disclosed vulnerability.

Article context

Mentioned in this article
Editorial credits

Follow the signal

Curated intelligence, delivered your way.

Never miss a market-moving update.

  • Daily briefingTop stories & analysis
  • Market movesKey charts & data
  • Policy updatesWhat to watch
  • Weekly deep diveLong-form insights

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line09.0714-08-2026
2Bitcoin purchases halted after data breach puts 250,000 crypto users at risk010.9217-08-2026
3В Ledger предупредили об ИИ-рисках на фоне взлома Coldcard-113.105-08-2026
4SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft012.317-08-2026
5Plunder Academy: Lowering the Barrier to Building on Zilliqa014.0826-01-2026
6Why crypto ‘audited’ badges are giving investors a dangerous false sense of security08.8509-08-2026
7Bitcoin Holders Lose $88,600,000 in Coldcard Crypto Wallet Exploit: Galaxy Researchers029.3203-08-2026
8Two Ethereum bridges lose $31.7M within hours as third protocol halts staking08.7825-07-2026
9Shipping partner breach exposes data of 14,000 Trezor customers010.0913-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 6.86. Источник: cryptoslate.com.