Zilliqa Ledger app vulnerability lets attackers recover keys
A Zilliqa Ledger app vulnerability can let attackers recover a signer’s private keys from publicly available onchain data. Zilliqa says signatures used predictably weakened ephemeral nonces, and users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised.
Key Takeaways
- The Zilliqa Ledger app vulnerability lets attackers reconstruct private keys using public onchain data.
- Weakened ephemeral nonces in signatures are the root of the key-recovery risk.
- Anyone who signed five or more native Zilliqa transactions with Ledger is treated as compromised.
- Zilliqa is finalizing remediation with Ledger; EVM-compatible ZIL tooling was not affected.
- Affected users should wait for official guidance before moving funds or signing more.
What is the Zilliqa Ledger app vulnerability?
Layer-1 network Zilliqa warned that a flaw in its Ledger hardware-wallet app can expose signer private keys. According to the project, signatures were generated with predictably weakened ephemeral nonces. From those weak nonces, an attacker can recover the signer’s private key using data already visible onchain.
Cointelegraph reported the warning in a Wednesday security alert covering Zilliqa’s disclosure. For more crypto security coverage, see our Fintech & Crypto Alerts hub.
Who is at risk from this Ledger flaw?
Zilliqa said users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised. The project advised those users to await further guidance before taking any action.
It also said users transacting ZIL through EVM-compatible tooling were not affected. That distinction matters for holders who only interacted via EVM paths rather than the native Ledger app flow.
How did Zilliqa respond to the breach risk?
Zilliqa said protective measures are already in place to prevent further losses, and a coordinated remediation plan is being finalized. It plans to publish a corrected version of the app in coordination with Ledger.
The warning follows a Monday request that exchanges temporarily pause Zilliqa (ZIL) deposits and withdrawals after Zilliqa identified a security vulnerability that led to the theft of an undisclosed amount of ZIL from a cold wallet.
What should ZIL Ledger users do now?
If you signed five or more native Zilliqa transactions on Ledger, treat your keys as potentially exposed and follow Zilliqa’s upcoming guidance before transferring assets or approving new signatures. Avoid ad-hoc rescue moves until the project and Ledger publish the corrected app and clear steps.
At publication, ZIL was trading above $0.0024 after a 1.5% drop over 24 hours and about 17% over the past week, according to CoinMarketCap figures cited by Cointelegraph. Hardware-wallet users should still prioritize key safety over short-term price moves.