Crypto
Home›Crypto›Regulation›Zilliqa warns Zilliqa Ledger app flaw could expose use…
Zilliqa warns Zilliqa Ledger app flaw could expose users private keys
Zilliqa said the issue involves weakened ephemeral nonces, and it advised users who signed at least five Zilliqa transactions with a Ledger device to await further guidance.
Zilliqa warned that a security vulnerability in the Zilliqa Ledger app could let attackers recover users private keys by reconstructing them from publicly available onchain data, according to Cointelegraph.
The blockchain network said the flaw causes signatures to be generated with predictably weakened ephemeral nonces, enabling a threat actor to recover a signer’s private key. Zilliqa added that protective measures are in place while a coordinated remediation plan is being finalized.
Zilliqa said users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised and should wait for additional guidance before taking action. It also said a corrected version of the app will be published in coordination with Ledger, and that users transacting ZIL through EVM-compatible tooling were not affected.
Cointelegraph also noted that the warning followed Zilliqa asking exchanges to temporarily pause ZIL deposits and withdrawals after it identified a vulnerability that led to theft of an undisclosed amount of ZIL from a cold wallet. At publication, the ZIL token was down 1.5% over the prior 24 hours and down 17% over the prior week, trading above $0.0024, per CoinMarketCap.