Zilliqa warns Ledger app flaw exposes private keys

Zilliqa warned a Ledger app flaw could let attackers recover private keys from predictable on-chain nonces; users with five or more native ZIL Ledger signatures are considered compromised.

Zilliqa warned Wednesday that a flaw in the Ledger app for its native token ZIL can allow attackers to recover private keys by exploiting predictably weakened ephemeral nonces visible on-chain.

The network wrote on X that the vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, ‘from which an attacker can recover the signer’s private key.’ Nonces are intended to be random and single-use; when they are predictable they can be reconstructed from public transaction data and used to derive the associated private key.

Zilliqa first alerted the market on Monday when it asked exchanges to temporarily pause ZIL deposits and withdrawals after detecting a security breach that resulted in the theft of an undisclosed amount of ZIL from a cold wallet. The team added that protective measures are in place and that a coordinated remediation plan with Ledger is being finalized.

The network advised that any user who signed at least five native ZIL transactions with a Ledger device should be considered compromised and should await official instructions before taking action. Addresses that transacted ZIL through EVM-compatible tooling are not affected by the issue.

ZIL’s market price moved lower after the disclosure, falling about 1.5% in the 24 hours before publication and roughly 17% over the prior week, trading above $0.0024. Exchanges that received Zilliqa’s request initially halted deposits and withdrawals while investigations continued.

On-chain exploitation of weak or repeated nonces is a known cryptographic risk: if an attacker can determine a nonce value from signatures or other public data, they can mathematically recover the private key used to create those signatures. Zilliqa is working with Ledger to publish an updated app and a remediation process intended to stop further unauthorized transfers while solutions are rolled out.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author