Zilliqa Flags Ledger App RNG Flaw That Could Expose Private Keys for Certain Native Transactions

AI Market Summary
Zilliqa disclosed a Ledger app RNG flaw that may allow recovery of private keys for a limited set of native transactions signed since 2019, prompting suspension of native transfers while guidance is prepared. Even if scope is constrained, the incident elevates counterparty and operational risk, likely pressuring Zilliqa-native liquidity and onchain activity short term. EVM transactions and associated SDKs are stated to be unaffected.
Impact level
● High
AI InsightAI Insight
▼ Bearish
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Zilliqa said it has identified a vulnerability in its Ledger application tied to random number generation that could allow private keys to be reconstructed for some Zilliqa native transactions. The issue affects native transactions signed between 2019 and 2026, with Zilliqa estimating the risk applies to five or more such transactions. Zilliqa explained that the most significant 64 bits of the random number were fixed at zero, reducing entropy and potentially enabling an attacker to recover private keys using onchain data. Zilliqa has suspended native transactions and urged users to wait for official instructions, advising against taking independent action. EVM transactions and related SDKs are not impacted, the company said.