Zilliqa Bug Exposes 6,772 Accounts, Enables Theft of 683 Million ZIL
A recent bug in Ledger's legacy signing path exposed at least 6,772 Zilliqa (ZIL) accounts and enabled thieves to steal an estimated 683.13 million ZIL across 66 successful transactions.
The theft was made possible due to a flaw in the Ledger application that discarded entropy, exposing private keys through four or more biased signatures.
Zilliqa's post-mortem investigation revealed that the first proven theft occurred on March 4, with the attacker's last transaction recorded on July 20. Legacy transactions were paused shortly after, and holders are awaiting a migration to Zilliqa EVM, pending an external security audit.