The flaw originated in how the Zilliqa Ledger app generated Schnorr signatures for non-EVM transactions. While the app produced sufficient random data, it incorrectly copied the values during the signing process, fixing the highest 64 bits of every nonce at zero. This lack of entropy enabled attackers to compare multiple public signatures from a single account and derive the corresponding private key using standard hardware.
Zilliqa detected evidence of active exploitation on July 19, prompting a swift suspension of native transfers. Although the team has developed a corrected app build, the fix cannot retroactively secure keys already exposed through onchain signatures. Consequently, the project has advised users who signed native transactions with a Ledger device to await official recovery instructions rather than attempting to move funds, which could allow an attacker to intercept or front-run the transfer.
While EVM-compatible transactions and the project's software development kits remain secure, the fallout has triggered wider market consequences. The South Korean exchange Upbit has placed ZIL under cautionary status, suspending deposits and withdrawals. Zilliqa credited KuCoin for assisting in the identification of the root cause, which followed an earlier report of a cold-wallet theft that the network has yet to explicitly link to this specific vulnerability.

Comments (0)
No comments yet. Be the first!