Close Menu
moneysguide.com

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How to Buy Gold | Money

    July 24, 2026

    Conagra Brands: A New Captain Sets A Leaner, Simpler Course, And I’m On Board (NYSE:CAG)

    July 24, 2026

    ‘It’s going to be a cultural shift’: Jody Mettler

    July 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How to Buy Gold | Money
    • Conagra Brands: A New Captain Sets A Leaner, Simpler Course, And I’m On Board (NYSE:CAG)
    • ‘It’s going to be a cultural shift’: Jody Mettler
    • In Treasury Management, to the Victor go the Spoils
    • Ether ETFs Add $26 Million as Bitcoin’s 7-Day Streak Ends
    • Nvidia, Meta, and Microsoft Tell Washington: Don’t Kill Open-Source AI
    • A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
    • Senate Dems should accept the victory they won on Trump’s crypto limits: White House
    moneysguide.com
    • Home
    • Business
      • Company News
      • Corporate Earnings
      • Entrepreneurship
      • Mergers & Acquisitions
      • Startups
    • Cryptocurrency
      • Altcoins
      • Bitcoin
      • Ethereum
      • Blockchain
      • DeFi
    • Economy
      • Global Economy
      • Government Policies
      • Inflation
      • Interest Rates
      • Recession
    • Finance
      • Personal Finance
      • Banking
      • Economy
      • FinTech
      • Investing
    • Forex
      • Forex News
      • Economic Calendar
      • Fundamental Analysis
      • Technical Analysis
      • Trading Signals
    • Investing
      • Dividend Investing
      • ETF Investing
      • Growth Investing
      • Portfolio Management
      • Value Investing
    • Stock Market
      • Asian Stocks
      • Earnings Reports
      • European Stocks
      • IPOs
      • US Stocks
    moneysguide.com
    Home»Cryptocurrency»Altcoins»A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
    Altcoins

    A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds

    AdminBy AdminJuly 24, 2026No Comments0 Views
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Zilliqa has suspended native transactions after discovering that roughly five affected signatures from the same private key may provide enough information to reconstruct that key, creating a recovery problem that an ordinary transfer cannot safely solve.

    The vulnerability is confined to Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app, according to the network’s security disclosure. Zilliqa said every version of the app released between 2019 and 2026 contained the flaw.

    Zilliqa said it detected on-chain activity consistent with active exploitation on July 19 and confirmed the root cause on July 21. The disclosure did not identify affected addresses or quantify any losses.

    Public signatures can expose the private key

    The flaw occurred while the Ledger app generated the ephemeral nonce required for each native Zilliqa signature. The signing routine generated 40 bytes of randomness and reduced the result modulo the secp256k1 curve order, but then copied the wrong 32-byte range into the nonce buffer.

    That operation retained eight zero-padding bytes while discarding eight bytes of actual entropy, fixing the nonce’s highest 64 bits at zero and leaving each value below 2192.

    Zilliqa said an attacker can combine approximately five affected signatures produced by the same private key and use lattice-reduction techniques to reconstruct that key within seconds on commodity hardware.

    Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should therefore be considered compromised, according to Zilliqa. The weakened signatures remain permanently available on-chain, so updating the app cannot remove the information already exposed. Affected private keys must ultimately be retired.

    Zilliqa credited KuCoin with reporting the incident and helping confirm the vulnerability. According to the disclosure, the exchange recovered affected private keys using publicly available signatures and assisted in tracing the problem to the app’s nonce-generation code.

    A normal rescue transfer could be front-run

    Moving assets to a new address once native transactions resume carries another risk. An attacker who has already reconstructed the private key can also sign a valid transaction and attempt to front-run the legitimate holder’s transfer.

    This leaves Zilliqa balancing two requirements before reopening native activity: allowing legitimate users to migrate their assets while preventing attackers with the same signing authority from winning the transaction race.

    CryptoSlate Daily Brief

    Daily signals, zero noise.

    Market-moving headlines and context delivered every morning in one tight read.

    5-minute digest 100k+ readers

    Free. No spam. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re subscribed. Welcome aboard.

    The network said it was finalizing a coordinated remediation plan and advised anyone who has signed native Zilliqa transactions with a Ledger device to await official instructions before taking action.

    Zilliqa suspended native, non-EVM transactions as a protective measure after identifying the vulnerability. The project said the pause halted further draining of affected accounts.

    At publication time, Zilliqa had not announced a reopening date or published its final migration procedure through its official channels.

    A corrected version of the Ledger app is being prepared in coordination with Ledger and will restore full-width nonce generation. The update can prevent future signatures from exposing the same information, but it cannot secure keys compromised by signatures already recorded on-chain. Zilliqa said release details would be announced separately.

    EVM and official SDK signing paths are unaffected

    The disclosure does not describe a compromise of Ledger hardware generally. Zilliqa attributed the vulnerability to its Ledger app’s implementation of native transaction signing.

    Zilliqa said EVM transactions are unaffected. The nonce-generation paths used by its official zilliqa-js, gozilliqa-sdk, and pyzil software development kits also fall outside the disclosed vulnerability.

    XRP Ledger nearly shipped a feature that could drain accounts without owners signingXRP Ledger nearly shipped a feature that could drain accounts without owners signing
    Related Reading

    XRP Ledger nearly shipped a feature that could drain accounts without owners signing

    Averted XRPL security threat underscores the network’s readiness for institutional adoption despite potential risks.

    Feb 28, 2026 · Oluwapelumi Adejumo

    attackers bug key Ledger lets Private rebuild seconds signatures year
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Admin
    • Website

    Related Posts

    New CLARITY Act update bans officials including presidents from issuing or even holding crypto tokens

    July 23, 2026

    Galaxy puts $5 million behind Bitcoin’s race to migrate before quantum risk arrives

    July 23, 2026

    Private equity allocations stabilise in H1 2026

    July 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Bitdeer’s Bitcoin Output Climbs to 990 as AI Cloud Run Rate Reaches $76M

    July 23, 20263

    Houthis claim strikes on two Saudi oil tankers in Red Sea

    July 23, 20263

    What should I ask Gita Gopinath?

    July 23, 20262

    South Korea’s Korbit exchange is now part of the $1 tillion Mirae Group family

    July 23, 20261
    Don't Miss
    Personal Finance

    How to Buy Gold | Money

    By AdminJuly 24, 20260

    Ads by Money. We may be compensated if you click this ad.Ad Gold hit record…

    Conagra Brands: A New Captain Sets A Leaner, Simpler Course, And I’m On Board (NYSE:CAG)

    July 24, 2026

    ‘It’s going to be a cultural shift’: Jody Mettler

    July 24, 2026

    In Treasury Management, to the Victor go the Spoils

    July 24, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    Welcome to MoneysGuide.com—your trusted source for the latest news, insights, and updates from the world of finance.

    Our mission is to make financial information accessible to everyone. Whether you're an investor, trader, entrepreneur, or simply interested in global markets, we provide timely coverage of the topics that matter most.

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    How to Buy Gold | Money

    July 24, 2026

    Conagra Brands: A New Captain Sets A Leaner, Simpler Course, And I’m On Board (NYSE:CAG)

    July 24, 2026

    ‘It’s going to be a cultural shift’: Jody Mettler

    July 24, 2026
    Most Popular

    Bitdeer’s Bitcoin Output Climbs to 990 as AI Cloud Run Rate Reaches $76M

    July 23, 20263

    Houthis claim strikes on two Saudi oil tankers in Red Sea

    July 23, 20263

    What should I ask Gita Gopinath?

    July 23, 20262
    © 2026 MoneysGuide.com. All Rights Reserved.
    • Privacy Policy
    • Terms and Conditions
    • Contact Us
    • About Us

    Type above and press Enter to search. Press Esc to cancel.