Zilliqa Ledger Vulnerability Exposes Private Keys via Predictable Random Number Generation
2026-07-22 16:40

Woofun AI reports that a critical vulnerability in the Zilliqa Ledger application compromises Schnorr signature generation for native transactions. The flaw, present in versions released between 2019 and 2026, stems from incorrect byte range copying during random number buffering, fixing up to 64 bits of entropy at zero. Attackers can predict nonces and recover private keys within seconds using lattice reduction on five or more signatures. On-chain exploitation was detected on July 19, with the root cause identified on July 21. Zilliqa has suspended native transactions and advised users to await official guidance, noting that EVM transactions and SDKs remain unaffected.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
Zilliqa
Ledger
zilliqa-js
gozilliqa-sdk
pyzil
Foresight News
EVM
Share:
back