Guavy AI Editorial TeamSentiment: -3Clout: 75

Zilliqa Users Warned of Private Key Compromise via Ledger App Flaw

Zilliqa, a Layer-1 blockchain network, has issued a warning to users about a vulnerability in its Ledger app. The flaw allows attackers to recover users' private keys by exploiting publicly available on-chain data.

The issue arises from signatures being generated with predictably weakened ephemeral nonces. An attacker can use this weakness to regain the signer's private key, compromising user security.

Zilliqa has implemented protective measures and is finalizing a coordinated remediation plan to prevent further losses. Users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised.

A corrective version of the app will be published in coordination with Ledger. Zilliqa also notes that users transacting ZIL through EVM-compatible tooling were not affected by this vulnerability.