Crypto
Home›Crypto›Market Structure›Zilliqa details Ledger bug that led to theft of 683.13…
Zilliqa details Ledger bug that led to theft of 683.13M ZIL
Zilliqa said the flaw discarded entropy during signing, forcing high bits of affected nonces to zero and enabling private-key reconstruction from biased signatures.
Zilliqa provided a post-mortem on a Ledger-related security issue that exposed private keys for at least 6,772 accounts and enabled theft of 683,130,969.66 ZIL, confirmed across 66 successful attack-window transactions, according to CryptoSlate.
The company said its legacy Ledger application generated 40 random bytes but copied the wrong 32 bytes into the signing buffer, leaving eight bytes of zero padding and discarding eight bytes of entropy. Zilliqa said that approach biased signatures by forcing the high 64 bits of affected nonces to zero.
Zilliqa added that four or more biased signatures produced for the same account could allow an attacker to reconstruct the private key from public blockchain data in seconds on ordinary hardware. It also said already-published signatures cannot be withdrawn, so a correction can protect new keys but cannot repair those already exposed.
The post-mortem also said the bulk scan behind the published exposure count requires at least five native signatures in a single signer era, which can omit accounts with exactly four signatures. Zilliqa said it traced the first proven theft to March 4, with anomalous activity later flagged by KuCoin and legacy transactions disabled around 12:59 UTC on July 20.