Seven-year Ledger bug exposed Zilliqa keys from five signatures

A Ledger app bug present since 2019 allowed private keys to be reconstructed from about five Zilliqa native signatures; Zilliqa paused non-EVM transactions and is planning a migration.

Zilliqa suspended native, non-EVM transactions after discovering a flaw in the Ledger app used to sign native Zilliqa transactions. The network detected suspicious on-chain activity on July 19, confirmed the root cause on July 21 and disclosed the vulnerability later in the month.

The bug affected the app’s implementation of Schnorr signatures for native transactions in every Ledger app version released between 2019 and 2026. The error occurred during ephemeral nonce generation: the signing routine produced 40 bytes of randomness, reduced the value modulo the secp256k1 curve order, then copied the wrong 32-byte range into the nonce buffer. That copy fixed the highest 64 bits of the nonce at zero and discarded eight bytes of entropy, producing nonces smaller than 2^192.

Because Schnorr signatures rely on unpredictable nonces, the biased values leaked information about the private key. Zilliqa reported that an attacker who collects roughly five signatures created with the same private key and the faulty nonces can reconstruct that key within seconds on commodity hardware using lattice-reduction techniques.

The compromised signatures are permanently recorded on-chain, so updating the app cannot erase exposed data. Any account that broadcast about five native transactions signed through the affected Ledger app should be considered compromised; affected private keys must be retired. The disclosure did not list affected addresses or quantify any losses.

Zilliqa credited the exchange KuCoin with reporting the incident and assisting in recovering some compromised keys and tracing the issue to the nonce-generation code. KuCoin used publicly available signatures to recover affected private keys, according to the network.

To limit further losses, the network paused native transactions while it finalizes a coordinated migration plan designed to prevent attackers who have reconstructed keys from front-running legitimate transfers. Zilliqa warned that moving assets immediately after native activity resumes could allow an attacker to sign and attempt to front-run a holder’s transfer and advised users who signed native transactions with a Ledger device to await official instructions.

The issue is specific to the Ledger app’s native transaction path. EVM transactions and the signing routes used by Zilliqa’s official software development kits — zilliqa-js, gozilliqa-sdk and pyzil — are not affected. Ledger is preparing a corrected app that restores full-width nonce generation to prevent future signatures from exposing the same weakness. Release details for the patched app and the final migration plan will be announced by Zilliqa.

Content on BlockPort is provided for informational purposes only and does not constitute financial guidance.
We strive to ensure the accuracy and relevance of the information we share, but we do not guarantee that all content is complete, error-free, or up to date. BlockPort disclaims any liability for losses, mistakes, or actions taken based on the material found on this site.
Always conduct your own research before making financial decisions and consider consulting with a licensed advisor.
For further details, please review our Terms of Use, Privacy Policy, and Disclaimer.

Articles by this author

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.