Search the site
Press ESC to close
LIVE
Loading...
Updating...

Zilliqa Alert: Vulnerability in Ledger App Risks ZIL Private Keys

Wei Liang Mo
Fact-checked
2 min read
351 words
Share

The Zilliqa team has identified a critical security vulnerability within the Ledger hardware wallet application specifically affecting native (non-EVM) ZIL transactions. The flaw involves a weakness in the generation of random numbers used for Schnorr signatures, potentially allowing malicious actors to reconstruct a user's private key. In response to the discovery, the network has suspended native transactions to protect users while a remediation plan is implemented.

Technical Details of the Random Number Flaw

The vulnerability stems from an error in the derivation of ephemeral random numbers, where the higher 64 bits of the generated value are consistently set to zero. This lack of entropy significantly weakens the cryptographic security of the signatures produced by the hardware wallet. According to technical assessments, an attacker monitoring the blockchain could exploit as few as five related on-chain transaction signatures to recover the underlying private key within seconds.

  • The flaw affects all versions of the Zilliqa Ledger app released since 2019.
  • Only native ZIL transactions are at risk; Ethereum Virtual Machine (EVM) compatible transactions remain secure.
  • Software-based tools and SDKs, such as zilliqa-js, gozilliqa-sdk, and pyzil, are not impacted by this specific hardware integration bug.

Mitigation and Impact on Exchange Operations

Zilliqa officials have clarified that simple asset transfers to a new address are insufficient to eliminate the risk if the original compromised key continues to be used. The development team is currently coordinating with Ledger to finalize a patched version of the application and is drafting a fund migration strategy for affected holders. Major cryptocurrency exchanges, including KuCoin, have been notified of the situation to ensure the security of user deposits and integrated services during this period of suspended native activity.

The current situation highlights the complexities of hardware-level cryptographic implementations and their long-term security implications. Users who have historically utilized the Zilliqa Ledger app for native transactions are advised to stay informed through official channels regarding the fund migration plan. As the fix is deployed, the transition will necessitate the discarding of affected keys to ensure the permanent security of assets on the Zilliqa blockchain.

Frequently Asked Questions

Quick answers to the most common questions about this topic.