A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

Share

Zilliqa suspended native transactions after discovering a flaw in its Ledger app that allows attackers to reconstruct a private key from approximately five signatures generated by the same key pair. The vulnerability, present in all app versions released between 2019 and 2026, affects nonce generation for Schnorr signatures on non-EVM transactions, retaining eight zero-padding bytes while discarding eight bytes of actual entropy. Exploitation was detected on July 19 and the root cause confirmed on July 21; KuCoin contributed to reporting and validating the issue. Signatures already recorded on-chain cannot be fixed, and attackers who have reconstructed a private key can front-run legitimate transfers, forcing Zilliqa to develop a coordinated migration plan before resuming native transactions. EVM transactions and signing paths used by official SDKs (zilliqa-js, gozilliqa-sdk, pyzil) remain unaffected by this flaw.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles