Zilliqa Ledger App Flaw Exposes Private Keys; 5 Native ZIL Transactions Needed to Recover Keys

ZIL-4.11%
Zilliqa disclosed today a critical random number vulnerability in its Ledger application affecting native ZIL transaction Schnorr signatures. The flaw generates temporary random numbers with the highest 64 bits fixed at zero, allowing attackers to recover private keys in seconds using approximately 5 related on-chain transaction signatures. The vulnerability has existed in all versions of the Zilliqa Ledger app since 2019. Native transactions have been suspended, and affected keys must be abandoned. EVM transactions and those using zilliqa-js, gozilliqa-sdk, or pyzil SDKs are unaffected. Zilliqa is coordinating with Ledger to release a patched version and develop a fund migration plan, with KuCoin assisting in confirming the vulnerability's cause and ongoing exploitation.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments