Zilliqa Bug Exposes Over 6,772 Accounts, Enables Theft of 683M ZIL
A recent bug in the Ledger application used by Zilliqa holders exposed at least 6,772 accounts and enabled the theft of over 683 million ZIL. The disclosure turned a previously unquantified security flaw into a measured loss record.
The issue occurred because the application generated 40 random bytes but copied only 32 bytes into its signing buffer, discarding eight bytes of entropy and retaining eight bytes of zero padding. This forced the high 64 bits of every affected nonce to zero.
Four or more biased signatures produced by the legacy Ledger application for the same account could then allow an attacker to reconstruct its private key from public blockchain data in seconds on ordinary hardware, according to Zilliqa.