Login
Sign Up
Woofun AI reports that Zilliqa has identified a critical security flaw within its official Ledger application, enabling attackers to reconstruct user private keys from public blockchain records. This vulnerability, which compromises the cryptographic integrity of digital signatures, has prompted immediate defensive measures across the network.
The technical root cause involves the generation of signatures using predictably weakened ephemeral nonces, a mechanism that allows adversaries to derive the signer’s private key. According to a Wednesday X post by Zilliqa, any user who executed at least five native Zilliqa transactions via a Ledger device is deemed compromised. While users relying on EVM-compatible tooling remain unaffected, the organization is finalizing a coordinated remediation plan to halt further exploitation.
Market reactions followed swiftly after Zilliqa requested exchanges to suspend ZIL deposits and withdrawals on Monday, citing an undisclosed theft from a cold wallet.
Woofun AI data shows the ZIL token declined 1.5% over 24 hours and 17% in the past week, trading above $0.0024 per CoinMarketCap. Compromised users are instructed to await official guidance before initiating any asset movements.
A corrected version of the application is being developed in direct coordination with Ledger to address the nonce generation failure. This incident underscores the persistent risks associated with hardware wallet integration on Layer-1 networks. The resolution timeline remains dependent on the joint technical efforts between the two entities.