September 24, 2026
Atlas21
ITA
podcast
news interviews learn feature industry opinion
Atlas21 B2B

Menu

Main categories

news interviews learn feature industry opinion

Secondary destinations

podcast Atlas21 B2B

Search Atlas21

Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Industry

Flaw in Zilliqa’s Ledger app exposes users’ private keys

Newsroom by Newsroom
July 23, 2026
in Industry
ledger bug
Share on FacebookShare on TwitterShare on Linkedin

Zilliqa reports that the vulnerability generates predictable ephemeral nonces, allowing an attacker to reconstruct a user’s private key from publicly available on-chain data.

Zilliqa warned on Wednesday that a vulnerability in the Ledger app dedicated to its network allows an attacker to reconstruct the signer’s private key using publicly available on-chain data. According to the post published on X, “the vulnerability causes the generation of signatures with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key.”

The problem lies in the generation mechanism for the ephemeral nonces used in the signing process. When these values are not sufficiently random, signatures produced across distinct transactions share patterns that make the private key algebraically extractable. Because the data is already written to the blockchain, the analysis can be performed retroactively on any past transaction: the exposure is not limited to future operations.

Zilliqa specified that users who have signed at least five native transactions via a Ledger device should be considered compromised. The network asked them to wait for coordinated guidance before acting independently. Protective measures have already been activated to prevent further losses, and a remediation plan is being finalised in collaboration with Ledger, which will release a corrected version of the app. Users who transacted via EVM-compatible tools are not affected by the flaw.

The incident follows by two days another warning from the same team: on Monday, Zilliqa had asked partner exchanges to temporarily suspend ZIL deposits and withdrawals after identifying a vulnerability that had already caused the theft of an undisclosed amount of tokens from a cold wallet. The connection between the two events indicates that the discovery of the nonce flaw is likely the technical cause of the theft that had already occurred, although Zilliqa has not explicitly confirmed this causal chain.

Ledger and Zilliqa have not yet announced a release date for the corrected version of the app.

Previous Post

Jack Dorsey launches Buzz, an open-source AI agent workspace built on Nostr

Next Post

When the BIS discovers its own irrelevance

Latest News

View of the Russian government building and bridge on a clear day in Moscow
Industry

Russia keeps Bitcoin payment ban and advances CBDC

by Newsroom
September 23, 2026
0

According to Tass, the digital ruble has been available for transactions since September 1

Read moreDetails
A cybersecurity expert inspecting lines of code on multiple monitors in a dimly lit office
Industry

579,900 USDT stolen by malicious App Store app

by Newsroom
September 23, 2026
0

Versions 1.1 and 1.2 included malicious modules

Read moreDetails
A lively crowd capturing an event on smartphones, showcasing modern digital engagement
Industry

EU Kids Act proposal sets age-based online access

by Newsroom
September 22, 2026
0

Age checks planned for social media and video-sharing platforms

Read moreDetails
Podcast

Manual of digital self-defense

by Federico Rivi
September 22, 2026
0

From mining pools to European digital surveillance, the second part of the interview with Tartequid brings together Bitcoin infrastructure and...

Read moreDetails
Skyline view of Riyadh's modern architecture with distinctive skyscrapers
Industry

FT: Saudi Arabia leaves mBridge CBDC project

by Newsroom
September 22, 2026
0

According to the Financial Times, SAMA ended its participation after a proof of concept

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team
  • Podcast
  • Home redesign preview

Follow Us

Atlas21
News Interviews Learn Feature Industry Opinion Podcast Atlas21 B2B

Social

X Instagram Nostr LinkedIn YouTube

Contact us

[email protected] Privacy Cookie

The rabbit hole has no bottom.

© 2026 Atlas21. All rights reserved.

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • Podcast
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.