|

A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

XRP Ledger nearly shipped a feature that could drain accounts without owners signing

Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the identical private key might present sufficient info to reconstruct that key, creating a restoration drawback that an unusual switch can’t safely resolve.

The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions by the Zilliqa Ledger app, in response to the community’s security disclosure. Zilliqa stated each model of the app launched between 2019 and 2026 contained the flaw.

Zilliqa stated it detected on-chain exercise in line with energetic exploitation on July 19 and confirmed the foundation trigger on July 21. The disclosure didn’t determine affected addresses or quantify any losses.

Public signatures can expose the private key

The flaw occurred whereas the Ledger app generated the ephemeral nonce required for every native Zilliqa signature. The signing routine generated 40 bytes of randomness and diminished the end result modulo the secp256k1 curve order, however then copied the unsuitable 32-byte vary into the nonce buffer.

That operation retained eight zero-padding bytes whereas discarding eight bytes of precise entropy, fixing the nonce’s highest 64 bits at zero and leaving every worth beneath 2192.

Zilliqa stated an attacker can mix roughly five affected signatures produced by the identical private key and use lattice-reduction methods to reconstruct that key inside seconds on commodity {hardware}.

Any account that has broadcast roughly five or extra native transactions signed by the Zilliqa Ledger app ought to due to this fact be thought of compromised, in response to Zilliqa. The weakened signatures stay completely obtainable on-chain, so updating the app can’t take away the knowledge already uncovered. Affected private keys should in the end be retired.

Zilliqa credited KuCoin with reporting the incident and serving to affirm the vulnerability. According to the disclosure, the exchange recovered affected private keys utilizing publicly obtainable signatures and assisted in tracing the issue to the app’s nonce-generation code.

A regular rescue switch may very well be front-run

Moving property to a new deal with as soon as native transactions resume carries one other danger. An attacker who has already reconstructed the private key may also signal a legitimate transaction and try and front-run the reputable holder’s switch.

This leaves Zilliqa balancing two necessities earlier than reopening native exercise: permitting reputable customers emigrate their property whereas stopping attackers with the identical signing authority from successful the transaction race.

The community stated it was finalizing a coordinated remediation plan and suggested anybody who has signed native Zilliqa transactions with a Ledger gadget to await official directions earlier than taking motion.

Zilliqa suspended native, non-EVM transactions as a protecting measure after figuring out the vulnerability. The challenge stated the pause halted additional draining of affected accounts.

At publication time, Zilliqa had not introduced a reopening date or revealed its last migration process by its official channels.

A corrected model of the Ledger app is being ready in coordination with Ledger and can restore full-width nonce era. The replace can forestall future signatures from exposing the identical info, but it surely can’t safe keys compromised by signatures already recorded on-chain. Zilliqa stated launch particulars could be introduced individually.

EVM and official SDK signing paths are unaffected

The disclosure doesn’t describe a compromise of Ledger {hardware} usually. Zilliqa attributed the vulnerability to its Ledger app’s implementation of native transaction signing.

Zilliqa stated EVM transactions are unaffected. The nonce-generation paths utilized by its official zilliqa-js, gozilliqa-sdk, and pyzil software program growth kits additionally fall outdoors the disclosed vulnerability.

XRP Ledger nearly shipped a feature that could drain accounts without owners signing
Related Reading

XRP Ledger nearly shipped a feature that could drain accounts without owners signing

Averted XRPL security threat underscores the network’s readiness for institutional adoption despite potential risks.
Feb 28, 2026
·
Oluwapelumi Adejumo

The put up A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds appeared first on CryptoSlate.

Similar Posts