Critical Flaw in Zilliqa's Ledger Application Exposes Users' Private Keys to Potential Theft

Critical Flaw in Zilliqa's Ledger Application Exposes Users' Private Keys to Potential Theft

Attackers can exploit a critical security flaw in Zilliqa's Ledger application to extract private keys by leveraging publicly accessible blockchain transaction data.

The Layer-1 blockchain platform Zilliqa has issued an alert regarding a critical flaw in its Ledger application that could enable malicious actors to extract users' private keys by analyzing publicly accessible blockchain transaction data.

"The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer's private key," Zilliqa said in a Wednesday X post.

According to Zilliqa, security safeguards have been implemented to mitigate additional losses, and a comprehensive remediation strategy is currently being finalized. Any users who have executed a minimum of five native Zilliqa transactions using a Ledger device should consider their wallets potentially compromised and should wait for additional instructions before proceeding with any actions.

The security alert follows Zilliqa's Monday request to cryptocurrency exchanges asking them to temporarily halt Zilliqa (ZIL) deposit and withdrawal services after the team discovered a security weakness that led to the unauthorized removal of an unspecified quantity of ZIL from a cold storage wallet.

Zilliqa announced it will release a patched version of the application in collaboration with Ledger. The company noted that users conducting ZIL transactions through EVM-compatible tooling remained unaffected by this vulnerability.

The ZIL token declined 1.5% in the past 24 hours and 17% over the past week, to trade above $0.0024 at publication, according to CoinMarketCap.

← Back to Blog