Today2h ago
Analytics
Zilliqa Halts ZIL Over a Ledger Key-Leak Bug

Zilliqa Halts ZIL Over a Ledger Key-Leak Bug

Zilliqa suspended all native ZIL transactions after attackers began exploiting a private-key-leaking bug in its Ledger wallet app that had been dormant since 2019.


The flaw is in how the Ledger app generates nonces for EC-Schnorr signatures: the top 64 bits are fixed at zero, so an attacker can rebuild a full private key from just ~5 on-chain signatures. ZIL was drained from an offline cold wallet run by an exchange partner; Upbit and others froze ZIL deposits and withdrawals. Zilliqa has not disclosed the amount and urges users to retire exposed keys and wait for a fix from Zilliqa and Ledger.