URGENT: Critical Flaw in Zilliqa Ledger App Exposes Private Keys!



​A severe security vulnerability has just been discovered in the Zilliqa Ledger application, prompting the network to take drastic protective measures.

The Vulnerability Explained
​According to Cointelegraph, the flaw lies in how the Zilliqa Ledger app generates transaction signatures.
​Weak Nonces: The application has been generating signatures using "predictably weakened ephemeral nonces".
​ Because these cryptographic nonces are mathematically predictable, sophisticated attackers can reverse-engineer and completely reconstruct a user's private key using nothing but publicly available on-chain transaction data.
​This alarming vulnerability reportedly affects all previous versions of the Zilliqa Ledger application.

​Zilliqa's Emergency Response
​To prevent attackers from sweeping users' hardware wallets, the Zilliqa team officially stepped in. The network has proactively suspended all native ZIL transactions. By halting transactions on the blockchain, they are preventing new, vulnerable signatures from being broadcasted, effectively buying time to patch the Ledger application.

​What Should You Do?
If you use a Ledger hardware wallet to secure your $ZIL , do not attempt to transact until an official software patch for the Zilliqa Ledger app is released by Ledger and the network officially resumes operations. Because this is an app-level software flaw (and not a hardware breach), your funds remain safe as long as your private keys aren't exposed through generating a new, vulnerable transaction signature.#zilliqa
ZIL-1.83%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
Add a comment
Add a comment
MimMallet
· 22h ago
Weak random number generation leads to private key leakage—a classic security flaw. Hardware wallet security depends on the upper-layer applications, and Ledger messed up this time, hurting users. Hopefully the patch goes live soon—please spread the word to everyone.
View OriginalReply1
AntiRugFarmer
· 23h ago
Oh wow, then I’m not moving my ZIL for now—I'll wait for the patch.
View OriginalReply1
ChainYugong
· 07-23 13:02
Thanks to the Zilliqa team for responding promptly! Pausing the network is a wise move to prevent new signature leaks. But do transactions that old users signed before also carry a risk? It’s recommended that all Ledger users contact the official team as soon as possible, update the app, and then proceed—don’t be tempted by short-term convenience.
View OriginalReply1
TechPioneer
· 07-23 13:01
This vulnerability is extremely critical. The signature is not predictable, and the attacker can reverse-engineer the private key. Pausing trading immediately is the right move—everyone, please don’t take any unnecessary action.
View OriginalReply1
  • Pinned