S&P 5007,785.76▼0.2% Nasdaq26,729.16▼0.3% Dow53,732.41▼0.2% Russell 2K3,068.42▲0.5% 10-Yr4.70%+6bp VIX14.25−0.38 WTI$82.40▲1.4% Gold$4,432.00▲1.6% EUR/USD1.157▲0.4% BTC$78,840▲1.4% Nikkei68,309▲1.2%
At close · Fri, Aug 14, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureZilliqa details Ledger bug that led to theft of 683.13…

Zilliqa details Ledger bug that led to theft of 683.13M ZIL

Zilliqa said the flaw discarded entropy during signing, forcing high bits of affected nonces to zero and enabling private-key reconstruction from biased signatures.

Zilliqa provided a post-mortem on a Ledger-related security issue that exposed private keys for at least 6,772 accounts and enabled theft of 683,130,969.66 ZIL, confirmed across 66 successful attack-window transactions, according to CryptoSlate.

The company said its legacy Ledger application generated 40 random bytes but copied the wrong 32 bytes into the signing buffer, leaving eight bytes of zero padding and discarding eight bytes of entropy. Zilliqa said that approach biased signatures by forcing the high 64 bits of affected nonces to zero.

Zilliqa added that four or more biased signatures produced for the same account could allow an attacker to reconstruct the private key from public blockchain data in seconds on ordinary hardware. It also said already-published signatures cannot be withdrawn, so a correction can protect new keys but cannot repair those already exposed.

The post-mortem also said the bulk scan behind the published exposure count requires at least five native signatures in a single signer era, which can omit accounts with exactly four signatures. Zilliqa said it traced the first proven theft to March 4, with anomalous activity later flagged by KuCoin and legacy transactions disabled around 12:59 UTC on July 20.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.