DeFi Daily News
Tuesday, September 8, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Markets Crypto Market

rewrite this title A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

Liam 'Akiba' Wright by Liam 'Akiba' Wright
July 24, 2026
in Crypto Market
0 0
0
rewrite this title A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1200 words and keep HTML tags

Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the same private key may provide enough information to reconstruct that key, creating a recovery problem that an ordinary transfer cannot safely solve.

The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, according to the network’s security disclosure. Zilliqa said every version of the app released between 2019 and 2026 contained the flaw.

Zilliqa said it detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. The disclosure did not identify affected addresses or quantify any losses.

Public signatures can expose the private key

The flaw occurred while the Ledger app generated the ephemeral nonce required for each native Zilliqa signature. The signing routine generated 40 bytes of randomness and reduced the result modulo the secp256k1 curve order, but then copied the wrong 32-byte range into the nonce buffer.

That operation retained eight zero-padding bytes while discarding eight bytes of actual entropy, fixing the nonce’s highest 64 bits at zero and leaving each value below 2192.

Zilliqa said an attacker can combine approximately five affected signatures produced by the same private key and use lattice-reduction techniques to reconstruct that key within seconds on commodity hardware.

Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should therefore be considered compromised, according to Zilliqa. The weakened signatures remain permanently available on-chain, so updating the app cannot remove the information already exposed. Affected private keys must ultimately be retired.

Zilliqa credited KuCoin with reporting the incident and helping confirm the vulnerability. According to the disclosure, the exchange recovered affected private keys using publicly available signatures and assisted in tracing the problem to the app’s nonce-generation code.

A normal rescue transfer could be front-run

Moving assets to a new address once native transactions resume carries another risk. An attacker who has already reconstructed the private key can also sign a valid transaction and attempt to front-run the legitimate holder’s transfer.

This leaves Zilliqa balancing two requirements before reopening native activity: allowing legitimate users to migrate their assets while preventing attackers with the same signing authority from winning the transaction race.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

The network said it was finalizing a coordinated remediation plan and advised anyone who has signed native Zilliqa transactions with a Ledger device to await official instructions before taking action.

Zilliqa suspended native, non-EVM transactions as a protective measure after identifying the vulnerability. The project said the pause halted further draining of affected accounts.

At publication time, Zilliqa had not announced a reopening date or published its final migration procedure through its official channels.

A corrected version of the Ledger app is being prepared in coordination with Ledger and will restore full-width nonce generation. The update can prevent future signatures from exposing the same information, but it cannot secure keys compromised by signatures already recorded on-chain. Zilliqa said release details would be announced separately.

EVM and official SDK signing paths are unaffected

The disclosure does not describe a compromise of Ledger hardware generally. Zilliqa attributed the vulnerability to its Ledger app’s implementation of native transaction signing.

Zilliqa said EVM transactions are unaffected. The nonce-generation paths used by its official zilliqa-js, gozilliqa-sdk, and pyzil software development kits also fall outside the disclosed vulnerability.

XRP Ledger nearly shipped a feature that could drain accounts without owners signing
Related Reading

XRP Ledger nearly shipped a feature that could drain accounts without owners signing

Averted XRPL security threat underscores the network’s readiness for institutional adoption despite potential risks.

Feb 28, 2026 · Oluwapelumi Adejumo

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AttackersbugKeyLedgerLetsPrivaterebuildrewriteSecondssignaturestitleYear
ShareTweetShare
Previous Post

rewrite this title Nvidia, Meta, and Microsoft Tell Washington: Don’t Kill Open-Source AI – Decrypt

Next Post

rewrite this title ‘I don’t know what will happen’ – Rafael Leao unsure over AC Milan future

Next Post
rewrite this title ‘I don’t know what will happen’ – Rafael Leao unsure over AC Milan future

rewrite this title 'I don't know what will happen' - Rafael Leao unsure over AC Milan future

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
US Orders Some Embassy Staff to Leave Baghdad on Iran Threat

US Orders Some Embassy Staff to Leave Baghdad on Iran Threat

June 12, 2025
rewrite this title Bitcoin’s Trajectory Towards 2026: A Comprehensive Price Outlook

rewrite this title Bitcoin’s Trajectory Towards 2026: A Comprehensive Price Outlook

July 15, 2025
The World Is Slowly Moving From the Dollar as Reserve Currency, Says Rabobank’s Foley

The World Is Slowly Moving From the Dollar as Reserve Currency, Says Rabobank’s Foley

March 6, 2025
Fed Chair Jerome Powell talks economy, rate cuts, and monetary policy with David Rubenstein

Fed Chair Jerome Powell talks economy, rate cuts, and monetary policy with David Rubenstein

July 15, 2024
rewrite this title Germany v Ivory Coast: Preview, predicted line-ups and where to watch

rewrite this title Germany v Ivory Coast: Preview, predicted line-ups and where to watch

June 19, 2026

Hormuz Deal Remains Elusive, Stocks Hold Near Record Highs | The Opening Trade 8/10/2026

August 10, 2026

Google Just WON The AI Race. That’s The Problem…

September 8, 2026

I spent $12,000 on the THINNEST Tech

September 8, 2026

My Dad Forced Me Into $184,000 of Car Debt (I’m 21)

September 8, 2026

Final Surviving Barstool S5 Recap Show

September 7, 2026

Crypto Is About To EXPLODE… Here’s What Happens Next

September 7, 2026

Is this the Real life? Is this just Fantasy……

September 7, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.