Zilliqa suspends native ZIL trading; a Ledger vulnerability allows attackers to “reconstruct private keys”

ZIL-1.84%
Key Takeaways
  • Zilliqa suspended native ZIL trading on July 22 after discovering Ledger's Schnorr signature nonce vulnerability from 2019.
  • Ledger's flaw locks the first 64 bits of each nonce to zero, allowing attackers to reconstruct private keys from five or more signatures.
  • Ledger is developing a fixed application version; native ZIL users on Ledger must await official instructions without transferring funds.

Zilliqa suspended native ZIL trading on July 22. Its investigation previously found a Schnorr signature nonce flaw in the Ledger hardware wallet app that has existed since 2019: the bug locks the first 64 bits of each signature nonce to zero, severely weakening randomness. This allows an attacker to reconstruct a private key from about 5 or more affected signatures, using only publicly available on-chain data.

Technical overview of Ledger’s 2019 Schnorr nonce vulnerability

According to Zilliqa’s official explanation, the fundamental technical cause of this vulnerability is as follows: Schnorr signatures require a unique and unpredictable random number (nonce) for each use. If the randomness of the nonce is weakened, the mathematical algorithm that protects the private key fails.

Zilliqa’s investigation found that when the Ledger app generates Schnorr signatures, it extracts the wrong 32 bytes from a 40-byte value, causing the first 64 bits of each nonce to be zero. Zilliqa describes this result as an “expected, weakened temporary nonce.”

An attacker only needs to obtain about 5 or more such affected signatures to reconstruct the signer’s private key from publicly available on-chain data. The vulnerability has existed since the Ledger app was released in 2019, and any qualifying signatures published after 2019 can be used for reconstruction.

Timeline of the July 19–22 incident: KuCoin assists with the demonstration; cold wallet was drained

According to Zilliqa’s official disclosure, the timeline is as follows: On July 19, Zilliqa detected on-chain activity consistent with exploitation; on July 20, a cold wallet belonging to a trading exchange partner of Zilliqa was hacked and the ZIL token was stolen. ZIL fell to a historical low of $0.002441. Coinone and KuCoin paused ZIL deposits and withdrawals; on July 21, Zilliqa identified the root cause; on July 22, it publicly disclosed the issue and suspended native ZIL trading.

KuCoin played a key role in this incident: it helped identify the nonce vulnerability and successfully reconstructed the affected private key from public signatures as a real-world demonstration. This confirmed the vulnerability had been exploited, enabling Zilliqa to take protective measures and develop a broader remediation plan.

User instructions and remediation progress: Ledger app fix version pending release

Based on Zilliqa’s official recommendations, the current instructions for affected users are as follows:

· Wait for official instructions: All users using Ledger hardware to sign native ZIL should wait

· Do not move any funds

· Do not attempt to fix it yourself

· EVM transaction and SDK users are not affected: users who only use EVM-compatible tools and the Zilliqa SDK do not need to take any action

· Ledger fixed version: Ledger is developing a fixed version of the Ledger app; the specific release time will be announced separately

As of the time of reporting on July 22, ZIL was trading at $0.00244 according to CoinGecko data, down 3.5% over the past 24 hours. Compared with the historical high of about $0.2563 in May 2021, it has fallen significantly.

FAQ

Why did Zilliqa suspend native ZIL trading on July 22?

According to Zilliqa’s official announcement on July 22, the reason was the discovery of the Schnorr signature nonce flaw in the Ledger app that has existed since 2019: the first 64 bits of each nonce are set to zero, allowing attackers to reconstruct private keys from approximately 5 or more affected public on-chain signatures.

Which types of ZIL users are affected?

According to Zilliqa, only users who sign native (non-EVM) ZIL transactions on Ledger hardware devices face risk. Users using EVM-compatible tools and the Zilliqa SDK are not affected.

When will the Ledger fixed version be released?

According to Zilliqa’s official statement, Ledger is developing a fixed version of the Ledger app; the specific release time will be announced separately. Users should follow Zilliqa and Ledger’s official channels for the latest announcements.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments