Foresight News
Foresight News|Jul 22, 2026 08:41
[Zilliqa Ledger App Vulnerability in Random Number Generation, Accounts Signing 5 or More Native Transactions May Be Compromised] Foresight News reports that Zilliqa has disclosed a critical vulnerability in its Ledger app, affecting the Schnorr signature generation for native (non-EVM) Zilliqa transactions. This vulnerability exists in all versions of the Zilliqa Ledger app released between 2019 and 2026. Signs of potential exploitation on-chain were detected on July 19, and the root cause was confirmed on July 21. The vulnerability allows the temporary random number (nonce) used during signature generation to be predictable, enabling attackers to reconstruct the private key of the signer using only publicly available on-chain data. Zilliqa advises users who have signed native Zilliqa transactions using Ledger devices to await official guidance and refrain from taking any independent actions. The root cause of the vulnerability lies in the signature program, which copied an incorrect byte range when writing the random number to the buffer, causing the highest 64 bits of each generated random number to be fixed at zero, resulting in severely insufficient entropy. By exploiting 5 or more affected signatures, attackers can use lattice reduction to reconstruct the private key within seconds. Since the affected transactions are permanently recorded on-chain, updating the signature application cannot mitigate this risk, and the associated private keys must be abandoned. Native transactions have been suspended to prevent further losses, and a coordinated remediation plan is in the final stages of confirmation. EVM transactions and SDKs such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads