Crypto
Home›Crypto›Market Structure›Zilliqa suspends native transactions after Ledger sign…
Zilliqa suspends native transactions after Ledger signature bug found
Zilliqa says native transactions signed via the Ledger app using Schnorr signatures could allow an attacker to reconstruct the private key with about five affected signatures in seconds, requiring compromised keys to be retired.
Zilliqa has suspended native transactions after identifying a vulnerability in the Zilliqa Ledger app that could expose users to private key recovery, creating a recovery problem that normal transfers cannot safely solve.
According to Zilliqa’s security disclosure, the flaw was limited to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, and it was present in every released app version between 2019 and 2026. The network said it detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21, though it did not name affected addresses or quantify any losses.
Zilliqa said the issue occurred during nonce generation, where the Ledger app generated the ephemeral nonce needed for each signature but copied an incorrect 32-byte range into the nonce buffer, fixing the nonce’s highest 64 bits at zero and leaving values below 2^192. It warned that an attacker could combine roughly five affected signatures produced by the same private key and use lattice-reduction techniques to reconstruct the key within seconds on commodity hardware, and that any account with about five or more such native transactions should be treated as compromised.
Because the weakened signatures remain permanently available on-chain, Zilliqa said updating the app cannot remove the exposed information and affected private keys must ultimately be retired. The network credited KuCoin with reporting the incident and helping confirm the vulnerability, and it said moving assets to a new address once native activity resumes could carry additional risk, including potential front running by an attacker who has reconstructed the key.