Overview
- Zilliqa detected active exploitation on Sunday, July 19, and after isolating the bug two days later it suspended all native ZIL transactions to stop further losses.
- The flaw came from copying 32 bytes into a 40-byte randomness buffer that left the top 64 bits of each EC-Schnorr nonce zeroed, which cuts the nonce entropy and enables lattice-reduction attacks.
- An attacker who collects about five or more affected on-chain signatures can reconstruct a private key, because the predictable top bits make the math tractable with commodity hardware.
- The problem is limited to the Ledger companion app’s native Zilliqa signing path and does not affect Ledger’s core hardware, Zilliqa SDKs, or EVM-compatible Ledger transactions.
- Exchanges including Upbit have halted ZIL deposits and withdrawals while Zilliqa and Ledger prepare a patched app that must be released, audited, and verified before native transactions resume, and affected users are being told to retire compromised keys and create new ones.