Zilliqa Ledger RNG Vulnerability Threatens Accounts With 5+ Signatures; Private Keys Recoverable

ZIL-3.45%
According to Zilliqa, on July 21 the project confirmed a critical random number generation vulnerability affecting its Ledger application for native Zilliqa transactions across all versions released from 2019 to 2026. The flaw in the signature process causes the nonce to have the top 64 bits fixed at zero, allowing attackers to recover private keys using only on-chain data if five or more affected signatures are available. Native transactions have been temporarily suspended. EVM transactions and the zilliqa-js, gozilliqa-sdk, and pyzil SDKs are not affected.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments