Zilliqa: Ledger Bug Exposed 6,772 Keys, Enabled 683M ZIL Theft
Zilliqa's post-mortem reveals a bug in the legacy Ledger application for Zilliqa discarded eight bytes of entropy when generating nonces, exposing the private keys of at least 6,772 accounts and enabling the theft of 683,130,969.66 ZIL across 66 transactions. Legacy transactions remain paused while migration to Zilliqa EVM awaits an external security audit.
This confirmed hardware-wallet security failure directly compromises user funds, and since already-published signatures cannot be withdrawn, exposed keys remain at risk permanently. It highlights how a subtle randomness bug in a signing implementation can undermine the security guarantees hardware wallets are trusted to provide, affecting ZIL holders using the legacy Ledger app and broader confidence in such devices.
The application generated 40 random bytes per nonce but copied the wrong 32 bytes into the signing buffer, keeping eight zero bytes and discarding eight entropy bytes, forcing the high 64 bits of each affected nonce to zero. Four or more such biased signatures for the same account allow private-key recovery in seconds from public blockchain data; the bulk scan required five signatures, so accounts with exactly four were not counted in the 6,772 figure.
rss · CryptoSlate · · Single source
Background, discussion, and references
Market impact
The affected asset is ZIL itself, so the transmission channel runs through on-chain liquidity and exchange operations: legacy transactions remain paused, deposits and withdrawals tied to the legacy path may be disrupted, and the confirmed compromise of thousands of keys could weigh on user confidence. Broader market impact is likely limited because ZIL is a relatively small-cap asset and the disclosed bug is confined to Zilliqa's legacy Ledger signing path, not the EVM side.
Background
ECDSA is an elliptic-curve digital signature scheme used by many blockchains; its security relies on the nonce (a random number used once) being unpredictable and unique. If the nonce is biased, an attacker who collects enough signatures can solve for the private key mathematically. This Zilliqa incident is similar in kind to the 2021 COLDCARD entropy failure, where a firmware migration caused the wallet to fall back to a deterministic software RNG, dramatically reducing seed entropy. Zilliqa is a blockchain that launched with its own native transaction format and is in the process of migrating to Zilliqa EVM, an Ethereum-compatible environment, which the team says is unaffected by this bug.
References
Tags
#Zilliqa#Ledger#hardware wallet#security#theft