August 24, 18:10

Zilliqa identifies Ledger flaw linked to 683 million ZIL theft

Zilliqa points to hardware wallet flaw discarding entropy to expose crypto keys, enabling 683M ZIL theft

CryptoSlate

Zilliqa identified a flaw in Ledger's legacy application that exposed private keys and enabled theft of 683,130,969.66 ZIL across 66 transactions. The post-mortem found that the application generated 40 random bytes but copied the wrong 32 bytes into its signing buffer. This discarded eight bytes of entropy and forced the high 64 bits of affected nonces to zero. Four or more biased signatures from the same account could allow attackers to reconstruct its private key from public blockchain data in seconds on ordinary hardware. The post-mortem identified at least 6,772 exposed accounts and 51 drained accounts. The exposed-account total could increase if investigators identify more theft transactions. The bulk scan required at least five native signatures, so it excluded accounts with exactly four signatures. Zilliqa's live address checker reports four-signature cases. Zilliqa traced the first proven theft to March 4 and disabled legacy transactions on July 20 around 12:59 UTC. Zilliqa said it wrote the original application implementation, while Ledger maintained it for years without finding the flaw. The issue does not affect Zilliqa EVM activity, recovery phrases, assets on other blockchains, or listed software-wallet signing paths. Zilliqa plans to migrate legacy holders to Zilliqa EVM, but it has not announced a launch date for the migration tool.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.