Login
Sign Up
Woofun AI reports that a critical vulnerability in the Zilliqa Ledger application compromises Schnorr signature generation for native transactions. The flaw, present in versions released between 2019 and 2026, stems from incorrect byte range copying during random number buffering, fixing up to 64 bits of entropy at zero. Attackers can predict nonces and recover private keys within seconds using lattice reduction on five or more signatures. On-chain exploitation was detected on July 19, with the root cause identified on July 21. Zilliqa has suspended native transactions and advised users to await official guidance, noting that EVM transactions and SDKs remain unaffected.