Summary: A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

Published: 30 days and 2 hours ago
Based on article from CryptoSlate

Zilliqa Halts Transactions to Mitigate Critical Ledger App Vulnerability

Zilliqa has officially suspended native transactions following the discovery of a critical security flaw in its dedicated Ledger application. The vulnerability, which affects non-EVM transactions, allows attackers to reconstruct private keys by analyzing just a handful of on-chain signatures. This preventive freeze aims to protect user assets while the network coordinates a complex recovery process for potentially compromised accounts.

A Flaw in Cryptographic Entropy

The root of the issue lies in how the Zilliqa Ledger app generated "nonces" for Schnorr signatures between 2019 and 2024. Due to a coding error, the application incorrectly handled randomness, fixing the highest 64 bits of the nonce to zero. This significant reduction in entropy means that anyone who has broadcast approximately five native transactions using a Ledger device may have inadvertently exposed enough information for an attacker to derive their private key. Using lattice-reduction techniques, a malicious actor could reconstruct these keys in seconds using standard hardware.

The Challenge of Asset Migration

While Zilliqa is working with Ledger to release a corrected version of the app, simply updating the software will not secure keys that have already been exposed on the blockchain. Affected users must eventually migrate their assets to entirely new addresses to ensure long-term security. However, this poses a "transaction race" risk, where an attacker with the reconstructed key could attempt to front-run a user’s migration transfer. Consequently, the network remains paused while developers finalize a remediation plan designed to give legitimate holders a safe path to move their funds.

Scope and Safety Measures

It is important to note that this vulnerability is specific to native Zilliqa transactions performed via the Ledger app and does not represent a general compromise of Ledger hardware. Transactions made through the Ethereum Virtual Machine (EVM) layer, as well as those signed using official Zilliqa SDKs (JavaScript, Go, or Python), remain unaffected. For now, Zilliqa advises all Ledger users to remain patient and wait for official instructions before attempting any movement of funds once the network resumes activity.

Cookies Policy - Privacy Policy - Terms of Use - © 2025 Altfins, j. s. a.