Skip to content
Back to Guavy Wire
Crypto

Zilliqa Bug Exposes Over 6,772 Accounts, Enables Theft of 683M ZIL

Instruments
ZIL
Share

A recent bug in the Ledger application used by Zilliqa holders exposed at least 6,772 accounts and enabled the theft of over 683 million ZIL. The disclosure turned a previously unquantified security flaw into a measured loss record.

The issue occurred because the application generated 40 random bytes but copied only 32 bytes into its signing buffer, discarding eight bytes of entropy and retaining eight bytes of zero padding. This forced the high 64 bits of every affected nonce to zero.

Four or more biased signatures produced by the legacy Ledger application for the same account could then allow an attacker to reconstruct its private key from public blockchain data in seconds on ordinary hardware, according to Zilliqa.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc