Zilliqa reports that the vulnerability generates predictable ephemeral nonces, allowing an attacker to reconstruct a user’s private key from publicly available on-chain data.
Zilliqa warned on Wednesday that a vulnerability in the Ledger app dedicated to its network allows an attacker to reconstruct the signer’s private key using publicly available on-chain data. According to the post published on X, “the vulnerability causes the generation of signatures with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key.”
The problem lies in the generation mechanism for the ephemeral nonces used in the signing process. When these values are not sufficiently random, signatures produced across distinct transactions share patterns that make the private key algebraically extractable. Because the data is already written to the blockchain, the analysis can be performed retroactively on any past transaction: the exposure is not limited to future operations.
Zilliqa specified that users who have signed at least five native transactions via a Ledger device should be considered compromised. The network asked them to wait for coordinated guidance before acting independently. Protective measures have already been activated to prevent further losses, and a remediation plan is being finalised in collaboration with Ledger, which will release a corrected version of the app. Users who transacted via EVM-compatible tools are not affected by the flaw.
The incident follows by two days another warning from the same team: on Monday, Zilliqa had asked partner exchanges to temporarily suspend ZIL deposits and withdrawals after identifying a vulnerability that had already caused the theft of an undisclosed amount of tokens from a cold wallet. The connection between the two events indicates that the discovery of the nonce flaw is likely the technical cause of the theft that had already occurred, although Zilliqa has not explicitly confirmed this causal chain.
Ledger and Zilliqa have not yet announced a release date for the corrected version of the app.





