A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the same private key may provide enough information to reconstruct that key, creating a recovery problem that an ordinary transfer cannot safely solve.
The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, according to the network's security disclosure. Zilliqa said every version of the app released between 2019 and 2026 contained the flaw.
Zilliqa said it detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. The disclosure did not identify affected addresses or quantify any losses.
Public signatures can expose the private key
The flaw occurred while the Ledger app generated the ephemeral nonce required for each native Zilliqa signature. The signing routine generated 40 bytes of randomness and reduced the result modulo the secp256k1 curve order, but then copied the wrong 32-byte range into the nonce buffer.
That operation retained eight zero-padding bytes while discarding eight bytes of actual entropy, fixing the nonce's highest 64 bits at zero and leaving each value below 2^192^.
Zilliqa said an attacker can combine approximately five affected signatures produced by the same private key and use lattice-reduction techniques to reconstruct that key within seconds on commodity hardware.
Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should therefore be considered compromised, according to Zilliqa. The weakened signatures remain permanently available on-chain, so updating the app cannot remove the information already exposed. Affected private keys must ultimately be retired.
Zilliqa credited KuCoin with reporting the incident and helping confirm the vulnerability. According to the disclosure, the exchange recovered affected private keys using publicly available signatures and assisted in tracing the problem to the app's nonce-generation code.
A normal rescue transfer could be front-run
Moving assets to a new address once native transactions resume carries another risk. An attacker who has already reconstructed the private key can also sign a valid transaction and attempt to front-run the legitimate holder's transfer.
This leaves Zilliqa balancing two requirements before reopening native activity: allowing legitimate users to migrate their assets while preventing attackers with the same signing authority from winning the transaction race.
The network said it was finalizing a coordinated remediation plan and advised anyone who has signed native Zilliqa transactions with a Ledger device to await official instructions before taking action.
Zilliqa suspended native, non-EVM transactions as a protective measure after identifying the vulnerability. The project said the pause halted further draining of affected accounts.
At publication time, Zilliqa had not announced a reopening date or published its final migration procedure through its official channels.
A corrected version of the Ledger app is being prepared in coordination with Ledger and will restore full-width nonce generation. The update can prevent future signatures from exposing the same information, but it cannot secure keys compromised by signatures already recorded on-chain. Zilliqa said release details would be announced separately.
EVM and official SDK signing paths are unaffected
The disclosure does not describe a compromise of Ledger hardware generally. Zilliqa attributed the vulnerability to its Ledger app's implementation of native transaction signing.
Zilliqa said EVM transactions are unaffected. The nonce-generation paths used by its official zilliqa-js, gozilliqa-sdk, and pyzil software development kits also fall outside the disclosed vulnerability.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

KORFIN and XRPL Korea Sign MOU for Digital Asset Business Collaboration
AI Wars II Is Here: WEEX Labs Launches Its Biggest Human vs. AI Trading Showdown Yet, Early Bird Round Opens Sept 3
WEEX Labs officially launches AI Wars II, the second season of its Human vs. AI trading championship. Early bird registration opens Sept 3-6, with the first 20,000 users sharing a 100,000 USDT prize pool. Register now.

Ethereum versus Solana: Which L1 captures more value?

Jobs, Warsh, and the FedWatch Reversal: What Comes Next for Bitcoin?
Kevin Warsh’s hawkish Jackson Hole speech has flipped the market’s September Fed expectations from “hold” toward a possible rate hike. With the August jobs report, CPI, and the FOMC decision arriving in quick succession, Bitcoin is entering a two-week macro stress test.

Important News from Last Night and This Morning (September 2 - September 3)

InfiniSoft and IoTrust Sign Agreement for AI Payment Based on WAIaaS

EIP-7906: Ethereum Security Proposal Under Evaluation

Saudi Arabia Confirms Death of Two Filipino Sailors in Iranian Attack on Oil Tanker

Weak ADP and Rising Treasuries: What Changes for Investors

What are NFTs and do non-fungible tokens still matter in 2026?

Stripe's Bridge Acquisition: Stablecoin Volumes Quadrupled

AI: Anthropic and Nvidia Enter the Realm of a Bitcoin Mining Giant

Tusk: Russia Uses Cryptocurrencies to Fund Terrorism in Poland

Crypto Will Eventually Merge with AI Finance

Ukraine Risks Receiving IMF Tranche of $1.66 Billion

September 2026 Crypto Market Outlook: Bitcoin, CPI, Fed Rate Hike Odds and WEEX Mini App Rewards

When AI Agents Gain On-Chain Execution Authority: Who Verifies the Information They See and the Commands They Issue?

Password Reset Issue on X: Thousands of Reports, But Is It an Attack?

$700 Million Annual Revenue, Yet Betting $10 Billion: IREN's Gamble for AI Computing Power

U.S. Energy Secretary Says Venezuela's Oil Production Will Double

Dropbox accounts compromised via Lenovo ID authentication flaw

War Cuts Dubai Airport Traffic by 31%, but Its Global Ambitions Remain Intact

2-3% of IBIT Inflows Come from Self-Custody Wallets

US PMI Falls in August: What This Means for Interest Rates and Investments

Microsoft 365 outage enters its second day with Outlook still unstable

Ethereum ETFs See Positive Inflows As September Trading Opens

€30,000 to Read a Contract Aloud: German Notary Fee Goes Viral After Musk's ‘Wow'

$40 Trillion U.S. Debt Alarm Sounds, BlackRock Unexpectedly Bullish on Bitcoin and Gold

Singapore proposes new stablecoin rules covering foreign issuers and interest

SEC and FDA sign 3-year market integrity pact
KORFIN and XRPL Korea Sign MOU for Digital Asset Business Collaboration
AI Wars II Is Here: WEEX Labs Launches Its Biggest Human vs. AI Trading Showdown Yet, Early Bird Round Opens Sept 3
WEEX Labs officially launches AI Wars II, the second season of its Human vs. AI trading championship. Early bird registration opens Sept 3-6, with the first 20,000 users sharing a 100,000 USDT prize pool. Register now.
Ethereum versus Solana: Which L1 captures more value?
Jobs, Warsh, and the FedWatch Reversal: What Comes Next for Bitcoin?
Kevin Warsh’s hawkish Jackson Hole speech has flipped the market’s September Fed expectations from “hold” toward a possible rate hike. With the August jobs report, CPI, and the FOMC decision arriving in quick succession, Bitcoin is entering a two-week macro stress test.










