Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
Zilliqa, a layer-1 blockchain network, has announced a vulnerability in the Zilliqa Ledger app that could allow attackers to recover users’ private keys by exploiting publicly available onchain data. According to Zilliqa's statement on X (formerly Twitter), the flaw causes signatures to be generated with weakened ephemeral nonces, enabling an attacker to potentially extract the signer’s private key. This issue specifically affects users who have signed at least five native Zilliqa transactions using a Ledger device.
Following the discovery of this vulnerability, Zilliqa requested exchanges on Monday to temporarily halt ZIL token deposits and withdrawals due to a security breach that led to the theft of an undisclosed amount of ZIL from a cold wallet. The company indicated protective measures are currently in place to prevent further losses, and it is working with Ledger to finalize a coordinated plan to fix the problem. A corrected version of the Zilliqa Ledger app will be released in due course, with the advisory that users involved in EVM-compatible transactions were not affected.
The market reaction to the vulnerability and theft has been notable, as the ZIL token price dropped by about 1.5% in the past 24 hours and 17% over the past seven days, trading above $0.0024 at the time of reporting according to CoinMarketCap. Zilliqa has urged affected users to await further guidance before taking any action, emphasizing that the situation is under active management and remediation efforts.