Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers

1 hour ago 1



Zilliqa has suspended native ZIL transactions after disclosing a critical flaw in its Ledger application that can allow attackers to recover private keys from public transaction signatures. Summary Zilliqa halted native transactions after a Ledger app flaw exposed private keys from public signatures. Accounts signing roughly five native transactions with Ledger devices should be treated as compromised permanently. Upbit flagged ZIL as cautionary while EVM transactions and Zilliqa software development kits remain unaffected. The bug affected every released version of the app from 2019 through 2026 and applies to native, non-EVM transactions signed with Ledger devices. The network said it observed onchain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. Zilliqa has prepared a corrected Ledger app build, but the fix cannot protect keys exposed through earlier signatures. Native transactions remained suspended in the latest official update while the team finalized a coordinated recovery plan. Zilliqa Ledger bug weakened transaction signatures The flaw affected how the Zilliqa Ledger app generated Schnorr signatures for native transactions...

Read Entire Article