Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys

Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys

A security vulnerability in the Zilliqa Ledger app is enabling attackers to reconstruct private keys using publicly available onchain data.

Layer-1 blockchain network Zilliqa warned that a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys using publicly available onchain data.

“The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key,” Zilliqa said in a Wednesday X post.

Zilliqa said protective measures are in place to prevent further losses and that a coordinated remediation plan is being finalized. Users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised and are advised to await further guidance before taking any action.

Read more

Comments (No)

Leave a Reply