Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

FATF Says Crypto Travel Rule Adoption Is Rising, But Enforcement Still Lags

July 24, 2026

DEXE crashes over 90% as Ceffu transfers raise DWF Labs questions

July 24, 2026

The Fraternal Order Of Police Supports The Clarity Act.

July 24, 2026
Facebook X (Twitter) Instagram
Friday, July 24 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

July 24, 2026Updated:July 24, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
Share
Facebook Twitter LinkedIn Pinterest Email
ad


Zilliqa has suspended native transactions after discovering that roughly 5 affected signatures from the identical non-public key might present sufficient data to reconstruct that key, making a restoration drawback that an strange switch can’t safely clear up.

The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions by the Zilliqa Ledger app, in line with the community’s safety disclosure. Zilliqa stated each model of the app launched between 2019 and 2026 contained the flaw.

Zilliqa stated it detected on-chain exercise in keeping with energetic exploitation on July 19 and confirmed the foundation trigger on July 21. The disclosure didn’t establish affected addresses or quantify any losses.

Public signatures can expose the non-public key

The flaw occurred whereas the Ledger app generated the ephemeral nonce required for every native Zilliqa signature. The signing routine generated 40 bytes of randomness and lowered the outcome modulo the secp256k1 curve order, however then copied the improper 32-byte vary into the nonce buffer.

That operation retained eight zero-padding bytes whereas discarding eight bytes of precise entropy, fixing the nonce’s highest 64 bits at zero and leaving every worth beneath 2192.

Zilliqa stated an attacker can mix roughly 5 affected signatures produced by the identical non-public key and use lattice-reduction strategies to reconstruct that key inside seconds on commodity {hardware}.

Any account that has broadcast roughly 5 or extra native transactions signed by the Zilliqa Ledger app ought to subsequently be thought of compromised, in line with Zilliqa. The weakened signatures stay completely obtainable on-chain, so updating the app can’t take away the data already uncovered. Affected non-public keys should in the end be retired.

Zilliqa credited KuCoin with reporting the incident and serving to verify the vulnerability. In keeping with the disclosure, the alternate recovered affected non-public keys utilizing publicly obtainable signatures and assisted in tracing the issue to the app’s nonce-generation code.

A traditional rescue switch could possibly be front-run

Transferring belongings to a brand new deal with as soon as native transactions resume carries one other danger. An attacker who has already reconstructed the non-public key also can signal a legitimate transaction and try to front-run the reputable holder’s switch.

This leaves Zilliqa balancing two necessities earlier than reopening native exercise: permitting reputable customers emigrate their belongings whereas stopping attackers with the identical signing authority from profitable the transaction race.

CryptoSlate Each day Temporary

Each day alerts, zero noise.

Market-moving headlines and context delivered each morning in a single tight learn.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, seems to be like there was an issue. Please attempt once more.

You’re subscribed. Welcome aboard.

The community stated it was finalizing a coordinated remediation plan and suggested anybody who has signed native Zilliqa transactions with a Ledger system to await official directions earlier than taking motion.

Zilliqa suspended native, non-EVM transactions as a protecting measure after figuring out the vulnerability. The undertaking stated the pause halted additional draining of affected accounts.

At publication time, Zilliqa had not introduced a reopening date or printed its remaining migration process by its official channels.

A corrected model of the Ledger app is being ready in coordination with Ledger and can restore full-width nonce technology. The replace can stop future signatures from exposing the identical data, nevertheless it can’t safe keys compromised by signatures already recorded on-chain. Zilliqa stated launch particulars could be introduced individually.

EVM and official SDK signing paths are unaffected

The disclosure doesn’t describe a compromise of Ledger {hardware} typically. Zilliqa attributed the vulnerability to its Ledger app’s implementation of native transaction signing.

Zilliqa stated EVM transactions are unaffected. The nonce-generation paths utilized by its official zilliqa-js, gozilliqa-sdk, and pyzil software program growth kits additionally fall outdoors the disclosed vulnerability.

A 7 year Ledger bug lets attackers rebuild a private key from five signatures in secondsXRP Ledger nearly shipped a feature that could drain accounts without owners signing
Associated Studying

XRP Ledger almost shipped a function that would drain accounts with out house owners signing

Averted XRPL safety menace underscores the community’s readiness for institutional adoption regardless of potential dangers.

Feb 28, 2026 · Oluwapelumi Adejumo



Source link

ad
Attackers bug Key Ledger Lets private rebuild Seconds Signatures Year
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

FATF Says Crypto Travel Rule Adoption Is Rising, But Enforcement Still Lags

July 24, 2026

DEXE crashes over 90% as Ceffu transfers raise DWF Labs questions

July 24, 2026

The Fraternal Order Of Police Supports The Clarity Act.

July 24, 2026

India’s IFF Calls BitChat GitHub Takedown Unconstitutional

July 24, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
FATF Says Crypto Travel Rule Adoption Is Rising, But Enforcement Still Lags
July 24, 2026
DEXE crashes over 90% as Ceffu transfers raise DWF Labs questions
July 24, 2026
The Fraternal Order Of Police Supports The Clarity Act.
July 24, 2026
A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
July 24, 2026
India’s IFF Calls BitChat GitHub Takedown Unconstitutional
July 24, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.