A flaw in Zilliqa’s Ledger application exposed at least 6,772 accounts and enabled the theft of 683,130,969.66 ZIL across 66 successful transactions. The technical defect stemmed from copying the wrong 32 bytes into the signing buffer, discarding eight bytes of entropy and forcing the high 64 bits of every affected nonce to zero. Four or more biased signatures generated for the same account by the legacy application could allow an attacker to reconstruct its private key from public blockchain data in seconds on ordinary hardware. The first proven theft dated back to March 4, KuCoin reported anomalies on July 19, and Zilliqa disabled legacy transactions the following day at 12:59 UTC, while migration to Zilliqa EVM awaits an external security audit.
Source: Read the original article

