A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the same private key may provide enough information to reconstruct that key, creating a recovery problem that an ordinary transfer cannot safely solve.
The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, according to the network's security disclosure. Zilliqa said every version of the app released between 2019 and 2026 contained the flaw.
Zilliqa said it detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. The disclosure did not identify affected addresses or quantify any losses.
Public signatures can expose the private key
The flaw occurred while the Ledger app generated the ephemeral nonce required for each native Zilliqa signature. The signing routine generated 40 bytes of randomness and reduced the result modulo the secp256k1 curve order, but then copied the wrong 32-byte range into the nonce buffer.
That operation retained eight zero-padding bytes while discarding eight bytes of actual entropy, fixing the nonce's highest 64 bits at zero and leaving each value below 2^192^.
Zilliqa said an attacker can combine approximately five affected signatures produced by the same private key and use lattice-reduction techniques to reconstruct that key within seconds on commodity hardware.
Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should therefore be considered compromised, according to Zilliqa. The weakened signatures remain permanently available on-chain, so updating the app cannot remove the information already exposed. Affected private keys must ultimately be retired.
Zilliqa credited KuCoin with reporting the incident and helping confirm the vulnerability. According to the disclosure, the exchange recovered affected private keys using publicly available signatures and assisted in tracing the problem to the app's nonce-generation code.
A normal rescue transfer could be front-run
Moving assets to a new address once native transactions resume carries another risk. An attacker who has already reconstructed the private key can also sign a valid transaction and attempt to front-run the legitimate holder's transfer.
This leaves Zilliqa balancing two requirements before reopening native activity: allowing legitimate users to migrate their assets while preventing attackers with the same signing authority from winning the transaction race.
The network said it was finalizing a coordinated remediation plan and advised anyone who has signed native Zilliqa transactions with a Ledger device to await official instructions before taking action.
Zilliqa suspended native, non-EVM transactions as a protective measure after identifying the vulnerability. The project said the pause halted further draining of affected accounts.
At publication time, Zilliqa had not announced a reopening date or published its final migration procedure through its official channels.
A corrected version of the Ledger app is being prepared in coordination with Ledger and will restore full-width nonce generation. The update can prevent future signatures from exposing the same information, but it cannot secure keys compromised by signatures already recorded on-chain. Zilliqa said release details would be announced separately.
EVM and official SDK signing paths are unaffected
The disclosure does not describe a compromise of Ledger hardware generally. Zilliqa attributed the vulnerability to its Ledger app's implementation of native transaction signing.
Zilliqa said EVM transactions are unaffected. The nonce-generation paths used by its official zilliqa-js, gozilliqa-sdk, and pyzil software development kits also fall outside the disclosed vulnerability.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

What are Bollinger Bands? The Trading Minute

Donald Trump to Resume White House Correspondents' Dinner After Attack That Forced Its Cancellation

Sealed In Foil: BMAG's New Focus On Trading Cards

Coinbase sees Bitcoin accumulation collide with Q3 macro pressure

Jennifer Tilly Earns Up to $10 Million a Year from The Simpsons Without Ever Participating: Her Story

SpaceX Shifts Focus to Starship, Leaving Falcon 9 Behind Amid Stock Price Inflection Point

Bitcoin Dev Kit 4.0 Launches Experimental Support for Silent Payments and BIP-353

Solana vs Monad Whitepaper Comparison (2026)

AI: Bitcoin Miners' Contracts Reach Equivalent of $150 Billion

Exaion: MARA Allegedly Concealed Its Mining Intentions in France, According to a Lawsuit Filed in the United States

Gas Rates Change: Redefining the Update System and Its Impact on Bills

Where is the smart money heading now?

Strategy Changes the Rules of the Game During a Bear Market. What Will Happen to the Company's Shares?

Mexico and the US conclude third round of trade negotiations on the T-MEC without agreements

OpenAI Sued by Pastor Who Claims ChatGPT's Medical Advice Worsened His Health Condition

HSBC Sells Insurance in Singapore for $2.1 Billion: What Changes

Dellepiane Highway to Close for 24 Hours for New Pedestrian Bridge Construction

Uniswap Token Jar: Unlocking Protocol Revenue Through Destruction, 11 Chains Have Launched This New Mechanism

Experts: "Banks are already preparing for a new era, and XRP may benefit the most"

$30,000 Investment Yields Only One User? The Decline of Influencer Marketing in Crypto

Multi-Chain Market: The Crypto Revolution That Surpasses Bitcoin Maximalism

Bitfinex completes El Salvador licence set across three markets

Brazil tokenizes cows as collateral in first B3 credit deal

Where Are the Arbitrage Opportunities in On-Chain Stock Perpetual Contracts?

Oil Alert: The Risk of a Major Spike Grows Due to the Crisis in the Middle East

Two weeks until SPiCE Southeast Asia 2026: Speakers share what’s to come

ETF: AI Attracts Billions from Wall Street as Crypto Changes Tracks

Ledger Hedging and New Stablecoin Path: In-Depth Analysis of Stripe's $53 Billion Acquisition of PayPal

Philippines’ BPI tests stablecoin rail for overseas remittances

