header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Zilliqa Ledger App Exposes Severe Vulnerability, Signing 5 Native Transactions Could Leak Private Key

BlockBeats News, July 22nd, Zilliqa announced that the Zilliqa Ledger app has a critical random number generation vulnerability, affecting Schnorr signatures of native non-EVM Zilliqa transactions. By utilizing only on-chain public data, an attacker can recover the signer's private key from a biased temporary random number.


Any account that has signed and broadcasted around 5 or more native transactions using the Zilliqa Ledger app should be considered compromised. Since the relevant signatures are permanently recorded on the blockchain, subsequent app updates cannot mitigate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, pyzil are not affected.


The vulnerability originated from selecting the wrong 32 bytes when replicating the random number in the app, retaining 8 bytes of zero padding and losing 8 bytes of entropy, causing the top 64 bits of each random number to be fixed at zero. An attacker can recover the private key within seconds using ordinary hardware with 5 or more affected signatures. Zilliqa observed suspected active exploitation on July 19th and confirmed the root cause on July 21st.


Zilliqa has temporarily paused native transactions to prevent further fund loss and is working with Ledger on a patched app. However, the patch cannot protect exposed keys, so affected users should not transfer assets on their own at the moment and should wait for the official announcement of a coordinated response plan.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish