Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Blockchain News

Zilliqa Reveals Five-Year Ledger Wallet Vulnerability Exposing Private Key

As the affected transactions are permanently recorded on-chain, this exposure cannot be reversed by updating the signing application.

Written By Dhara Chavda
Edited by Divya Mistry
Published 2026-07-22·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Zilliqa Reveals Five-Year Ledger Wallet Vulnerability Exposing Private Key

Zilliqa has publicly disclosed a serious, long-standing vulnerability in its official Ledger hardware wallet application that allows attackers to recover private keys belonging to users who have signed multiple native (non-EVM) Zilliqa transactions.

The issue, present in every version of the Zilliqa Ledger app since its launch in 2019, stems from a flaw in ephemeral nonce generation during Schnorr signature creation. As a result, the most significant 64 bits of every affected nonce were fixed at zero, enabling private key recovery from as few as five on-chain signatures using standard lattice reduction techniques.

AI Summary
Show
Zilliqa’s remediation plan to secure affected balances is being finalized, with users advised to await official communications before taking action
A corrected Ledger app version is prepared to prevent future vulnerabilities, but existing exposed keys remain at risk, requiring retirement
The incident underscores the importance of correct nonce handling and implementation in signature schemes, with Zilliqa promising a full post-mortem report

Investigation and clarification

The disclosure follows an investigation launched after on-chain activity consistent with active exploitation was observed on July 20, 2026. Initially, suspicion fell on exchange wallet management, but Zilliqa’s probe quickly ruled this out. In a July 20 update, the project confirmed no evidence pointed to exchange-side issues and instead isolated the problem to a technical flaw in the Ledger app’s native transaction signing path.

KuCoin played a central role in the investigation. The exchange reported the issue, recovered affected private keys from publicly available on-chain data, and helped confirm ongoing exploitation. Zilliqa praised KuCoin’s “professionalism, technical expertise, and cooperation.”

Root cause

Zilliqa native transactions use EC-Schnorr signatures over the secp256k1 curve. Each signature requires a fresh, uniformly random 256-bit ephemeral nonce (k). The signing routine correctly generated 40 bytes of randomness and reduced it modulo the curve order to produce a uniform value. However, when copying the result into the nonce buffer, the code selected the wrong 32 bytes — retaining eight zero-padding bytes from the reduction process and discarding eight bytes of actual entropy.

This caused every generated nonce to satisfy k < 2¹⁹². With 64 known bits, each signature leaks information about the private key. After roughly five such signatures, the private key can be reconstructed efficiently on commodity hardware.

The bug was confined exclusively to the Ledger app’s native (non-EVM) signing path. EVM-compatible transactions and all official Zilliqa software development kits (zilliqa-js, gozilliqa-sdk, pyzil) remain unaffected.

Impact

Any account that has broadcast approximately five or more native Zilliqa transactions signed through the Zilliqa Ledger app should be considered compromised. Because the weakened signatures are permanently recorded on-chain, the exposure cannot be reversed by updating the app. Affected private keys must be retired.

Zilliqa emphasized that simply transferring funds out would be ineffective and potentially unsafe. An attacker in possession of the derived private key could attempt to front-run any legitimate transaction once activity resumes.

Protective measures and remediation

As soon as the root cause was confirmed on July 21, Zilliqa suspended native (non-EVM) transactions as a protective measure. This has halted further draining of affected accounts.

A corrected version of the Ledger app, restoring full-width nonce generation, has been prepared in coordination with Ledger. Release details will be announced separately. However, the fix only prevents future weakened signatures — it does not protect keys already exposed through prior transactions.

A coordinated remediation plan to secure affected balances is being finalized and will be published through official Zilliqa channels. Until then, users who have signed native Zilliqa transactions with a Ledger device are advised to take no independent action and to rely solely on official communications.

Broader context

The incident highlights the critical importance of correct nonce handling in elliptic-curve signature schemes and the permanent nature of on-chain data. While hardware wallets are widely trusted for key security, implementation bugs in supporting applications can still create systemic risks.

Zilliqa stated it will publish a full post-mortem, including detailed technical findings and recommended actions, once the investigation concludes.

Users holding or transacting ZIL exclusively through EVM-compatible tooling or non-Ledger wallets are not affected by this vulnerability. Zilliqa continues to work with Ledger and ecosystem partners on the remediation plan. The project has urged the community to monitor official channels for further updates.

Also Read: Coinbase Outage: Kubernetes Config Conflict Cause 50-Min Disruption

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Cryptocurrency
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

India’s FIU Orders Takedown of 15 Offshore Crypto Apps Over AML Non-Compliance
India’s FIU Orders Takedown of 15 Offshore Crypto Apps Over AML Non-Compliance
Hand holding smartphone displaying BitMart crypto exchange logo against monitor background
BitMart Hires Alvarez & Marsal as Financial Adviser While Users Await Withdrawal Clarity
Stressed doctor holding head while looking at crypto portfolio losses on laptop screen
Shown ₹14 Cr Profit, Bengaluru Doctor Loses ₹4.47 Cr in India Crypto Trap
Gemini crypto exchange logo displayed on smartphone screen over laptop keyboard
Gemini Secures Singapore MPI License for Crypto Services
Gold Bitcoin coin resting on a fabric national flag of Iran
Iran Relaxes Crypto Rules as Exporters Settle Trade in Tether, FT Reports

Find Us on Socials

You may also like

Gold Bitcoin token displayed on a marble pedestal in front of a dark wall with the Strive company logo.

Strive Acquires 1,375 BTC, Holdings Reach 24,531

Silver Ethereum ETH coins placed in front of a BitMine wall logo reading The Alchemy of 5%

BitMine Adds 28,086 ETH, Treasury Hits 5.93M Tokens Worth $15.7B

CLARITY Act bill document for digital assets regulation on a desk next to law books and US flag

Crypto Group Launches Seven-Figure Ad Blitz for CLARITY Act, Attacking Banks

Judge holding a gavel next to a laptop showing seized and rejected crypto wallets with US Capitol background

US Judge Seizes One Crypto Wallet, Rejects 7 Others Over Forfeiture Notice

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information