๐Ÿ“… Sunday, 13 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Semua Aplikasi Ledger Zilliqa Sejak 2019 Bocorkan Private Key - Modalnya Cuma 5 Transaksi Biasa

All Zilliqa Ledger Apps Since 2019 Leak Private Keys - Requiring Just 5 Regular Transactions

Zilliqa took emergency action by suspending all native ZIL transactions after discovering a critical security flaw in its Ledger app. The bug allows attackers to recover private keys directly from freely available public signatures. This vulnerability impacts all Ledger app versions released from 2019 to 2026, specifically targeting native non-EVM transactions signed using Ledger hardware.

Initial suspicions arose on July 19, 2026, when network observers spotted on-chain activity consistent with an active exploit. Zilliqa confirmed the technical root cause two days later on July 21, 2026, revealing the primary issue stemmed from a code memory-copying error.

The Zilliqa Ledger app generated sufficient random data to produce secure Schnorr signature nonces. However, during the final processing stage, the system copied the wrong 32 bytes of data. This copying mistake diminished randomness, leaving the top 64 bits of every nonce filled with zeros and compromising the core defense of hardware wallet security.

Five Transactions to Unlock Keys

The reduction in cryptographic randomness opened an easy pathway for hackers. An attacker only needs to compare several public signatures from the same account to reconstruct the private key. The attack requires minimal effort and no specialized tools, allowing key recovery within seconds on a standard home computer.

Accounts that have executed five or more native transactions are confirmed to be compromised. KuCoin stepped in to verify the severity of the flaw, confirming active exploitation after its engineers successfully recovered a user private key from public signatures alone. Users transacting exclusively via EVM remain unaffected, as the vulnerability is isolated to Zilliqa’s native signing pathway.

Permanent Traces on the Blockchain

New application updates cannot resolve the issue for existing users. Public signatures from past transactions remain permanently recorded on the public blockchain ledger for anyone to view. An updated app cannot conceal or protect keys that have already been exposed, leaving key retirement as the only way to prevent theft.

The impact quickly reached cryptocurrency trading markets. Upbit placed ZIL under caution trading status to protect users, while South Korea’s largest digital asset exchange also suspended all ZIL deposits and withdrawals indefinitely.

Developers have confirmed that a fix for the Ledger app is complete, though the final update has not yet been released to the public. Comprehensive asset recovery guidelines are also pending. For affected wallet holders, old keys cannot be salvaged, leaving them with no choice but to await official instructions before transferring remaining funds to a new wallet. Reported by crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share