Zilliqa freezes ZIL transfers as 2019 Ledger flaw exposes private keys
Zilliqa halted native ZIL transfers after a 2019 Ledger app bug let attackers rebuild private keys from public signatures.

On Wednesday, Zilliqa froze native ZIL transactions. The blockchain had a flaw in its Ledger app dating back to 2019. The bug allowed attackers to reconstruct private keys from signatures already on the blockchain.
Anyone who has signed a native ZIL transfer with a Ledger device is at risk. The vulnerability was confirmed by Zilliqa in an X post. The vulnerability is in the way the Ledger app generates Schnorr signatures for native, non-EVM ZIL transactions.
Holders who only use EVM-compatible tools and the Zilliqa SDKs to transact ZIL will not be affected. A 32-byte copy bug broke the signature randomness A Schnorr signature needs a random number, which must be unique. That is what is called a nonce.
It has to be secret and unpredictable for each signing. If the randomness is weakened, the math that protects the private key breaks down. Zilliqa said the signing routine was pulling the wrong 32 bytes from a 40-byte value.
That left zero for the top 64 bits of every nonce. Zilliqa described the result as “predictably weakened ephemeral nonces.” Strip out that much randomness, and an attacker with about five or more such signatures could reconstruct the signer’s private key.
All that’s needed is public on-chain data, the team said. The bug has been there since 2019. Any qualifying signature published since then is fair game for reconstruction.
Zilliqa was crystal clear on the blast radius. Only native ZIL transactions signed on Ledger hardware are exposed. Nothing else is.
EVM transactions are clear. And the SDKs are clear too. For now, Zilliqa told anyone who has signed native ZIL with a Ledger to wait.
Don’t move any funds, don’t try a fix yourself, wait for official instructions. Zilliqa said it has already taken protective measures to prevent any further losses and is working on a remediation plan. Ledger is itself working on a patched version of the Ledger app and timing will be announced at a later date.
KuCoin flags exploit as ZIL takes second hit This was not
Đọc thêm từ Tiền số / Crypto

Alphabet’s Google Cloud revenue surges 82% in Q2 2026, but market remains cautious
Alphabet's Google Cloud revenue surged 82% in Q2 2026, but skepticism remains with odds for it being the second-largest company at just 3.5% YES. The post Alphabet’s Google Cloud revenue surges 82% in Q2 2026, but market remains cautious appeared first on Crypto Briefing.

Democrats Reject CLARITY Act Draft as Crypto Ethics Dispute Intensifies
Seven Senate Democrats rejected the latest CLARITY Act draft, saying it does not go far enough on ethics, consumer protection, and illicit finance, while Republicans argue the bill contains the strongest federal ethics rules ever proposed for digital assets. Democrats Say Draft S

CLARITY Act faces Senate setback over ethics concerns
Seven Democratic Senators issued a joint statement on Tuesday afternoon opposing the current text of the CLARITY Act, the Senate’s crypto market structure bill, telling Republicans the draft falls short on key provisions including “ethics for elected officials, consumer protectio

US airstrike kills two at Shalamcheh border crossing: Iran state media
US airstrike kills two at Shalamcheh border crossing. Iranian regime fall by end of 2026 now at 10.5% YES. The post US airstrike kills two at Shalamcheh border crossing: Iran state media appeared first on Crypto Briefing.