Zilliqa Warns of Private Key Recovery Vulnerability in Ledger App
Zilliqa, a Layer-1 blockchain network, has discovered a vulnerability in its Ledger app that allows attackers to recover users' private keys using publicly available on-chain data.
The weakness generates signatures with predictably weakened ephemeral nonces, making it possible for an attacker to obtain the signer's private key. To mitigate further losses, Zilliqa is implementing protective measures and finalizing a coordinated remediation plan with Ledger.
User who signed at least five native Zilliqa transactions using a Ledger device are considered compromised and are advised to await further guidance before taking any action.




