📅 Monday, 14 September 2026 · --:-- UTC Follow us
Ecosystem
ID EN
Aplikasi Ledger Zilliqa Bocorkan Private Key ke Publik - Lima Transaksi Cukup Buat Bobol Dompet

Zilliqa Ledger App Leaks Private Keys Publicly - Five Transactions Enough to Compromise Wallets

Developers of the Zilliqa network disclosed a critical vulnerability within the Zilliqa Ledger app on Wednesday, July 22, 2026. The bug serves as a fatal flaw allowing attackers to reconstruct users’ private keys by relying solely on publicly accessible onchain activity data.

The vulnerability threshold threatening users is remarkably low. Anyone who has signed at least five native ZIL transactions using a Ledger device is now confirmed to be compromised. The root of the issue stems from the digital signature generation process itself. Transaction signatures on the network were apparently generated using ephemeral nonces - single-use random numbers - that were weakened to a predictable pattern. From this flawed pattern, attackers have sufficient data to fully recover the signer’s private key.

Traces of Exploitation Since Early in the Week

The announcement regarding the compromised Ledger app marks the culmination of a series of unusual events over the past few days. High-level alarm bells were already sounded on Monday when the Zilliqa team circulated specific instructions to various exchanges, requesting all trading platforms to immediately suspend ZIL coin deposits and withdrawals without exception.

The exchange suspensions were initiated right after the security team detected a vulnerability that led to active exploitation in the wild. ZIL tokens were stolen directly from several cold wallets - a storage infrastructure meant to serve as the most secure vault for investors. However, as of this latest announcement, Zilliqa has remained tight-lipped about the exact amount of stolen funds.

As a containment measure, Zilliqa emphasized that multi-layered protective procedures were immediately implemented to prevent further losses. The team is currently designing a coordinated remediation plan for affected parties. Working alongside Ledger’s internal engineers, Zilliqa promised to release a patched version of the app as quickly as possible.

Unaffected Users and Market Reaction

Amid concerns surrounding the security of these hardware wallets, one group of users has managed to stay safe from the exploit. Users who have been processing ZIL transactions through EVM (Ethereum Virtual Machine) compatible setups are confirmed to be completely unaffected by the Ledger app bug.

Nonetheless, sentiment around the critical vulnerability quickly dragged down trading enthusiasm across exchanges. ZIL dropped 1.5% over the past 24 hours. The daily downward pressure compounded a broader sell-off that had already cut its valuation by 17% over the past week, leaving the token hovering just above the $0.0024 level.

The Zilliqa Ledger app incident shatters a fundamental sense of security for investors. When a hardware wallet fails to safeguard its keys due to flawed underlying mathematics, the strongest remaining defense is nothing more than how quickly a network can pull the emergency brake. Reported by Cointelegraph.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
📩 KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share