Zilliqa Flags Critical Ledger App Nonce Flaw That Can Expose ZIL Private Keys
AI Market Summary
Zilliqa disclosed a critical nonce-generation flaw in its Ledger app affecting Schnorr signatures for native (nonEVM) ZIL transfers, enabling private-key recovery within seconds from a handful of signatures. The bug reportedly impacts all app versions since 2019, prompting suspension of native transactions and requiring users to abandon affected keys. The incident heightens counterparty and custody risk, likely pressuring liquidity and confidence around ZIL while remediation and key rotation proceed.
Impact level
● High
AI InsightAI Insight
▼ Bearish
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
PANews, July 22 — Zilliqa said it has uncovered a critical vulnerability in the Zilliqa Ledger app involving nonce generation for Schnorr signatures used in native (non-EVM) ZIL transactions. The issue forces the 64 most significant bits of the temporary nonce to be zero, allowing attackers to recover private keys in seconds with as few as around five on-chain transaction signatures. Zilliqa noted the flaw has been present in every version of the Zilliqa Ledger app since 2019. The network has suspended native transactions and warned that affected keys should be discarded. The team added the risk cannot be fully eliminated through standard fund transfers alone.