Zilliqa freezes ZIL transfers as 2019 Ledger flaw exposes private keys

Wait 5 sec.

On Wednesday, Zilliqa froze native ZIL transactions. The blockchain had a flaw in its Ledger app dating back to 2019. The bug allowed attackers to reconstruct private keys from signatures already on the blockchain. Anyone who has signed a native ZIL transfer with a Ledger device is at risk.The vulnerability was confirmed by Zilliqa in an X post. The vulnerability is in the way the Ledger app generates Schnorr signatures for native, non-EVM ZIL transactions. Holders who only use EVM-compatible tools and the Zilliqa SDKs to transact ZIL will not be affected.A 32-byte copy bug broke the signature randomnessA Schnorr signature needs a random number, which must be unique. That is what is called a nonce. It has to be secret and unpredictable for each signing. If the randomness is weakened, the math that protects the private key breaks down.Zilliqa said the signing routine was pulling the wrong 32 bytes from a 40-byte value. That left zero for the top 64 bits of every nonce. Zilliqa described the result as “predictably weakened ephemeral nonces.” Strip out that much randomness, and an attacker with about five or more such signatures could reconstruct the signer’s private key. All that’s needed is public on-chain data, the team said.The bug has been there since 2019. Any qualifying signature published since then is fair game for reconstruction.Zilliqa was crystal clear on the blast radius. Only native ZIL transactions signed on Ledger hardware are exposed. Nothing else is. EVM transactions are clear. And the SDKs are clear too. For now, Zilliqa told anyone who has signed native ZIL with a Ledger to wait. Don’t move any funds, don’t try a fix yourself, wait for official instructions.Zilliqa said it has already taken protective measures to prevent any further losses and is working on a remediation plan. Ledger is itself working on a patched version of the Ledger app and timing will be announced at a later date.KuCoin flags exploit as ZIL takes second hitThis was not theoretical. Zilliqa said on July 19 that it had detected on-chain activity consistent with exploitation. On July 21 it found the root cause. It went public on July 22. The incident adds to what has already been the most hacked quarter on record for crypto.KuCoin was specifically credited by Zilliqa for the diagnosis. Zilliqa said KuCoin helped identify the nonce bug. As a demonstration, the exchange retrieved affected private keys from public signatures, confirming the exploit was in use. The cooperation allowed Zilliqa to move on protective measures and build out the wider fix, the project said.On July 20, just days before the Ledger disclosure, Zilliqa revealed that ZIL had been stolen from a cold wallet of one of its exchange partners. This sent the token to a new all-time low of $0.002441. It also prompted Coinone and KuCoin to halt ZIL deposits and withdrawals, Cryptopolitan reported at the time.Such thefts became a trend this year after an attacker drained $820,000 from the privacy protocol Hinkal earlier in July. CEO Alexander Zahnd called for calm. He said he’d give a full report.Zilliqa has not said if the two events are related. All week ZIL was under pressure. ZIL down 3.5% over the past 24 hours to $0.00244 according to CoinGecko data. ZIL hit a high of ~$0.2563 in May 2021.The smartest crypto minds already read our newsletter. Want in? Join them.