Loading prices…
🩸BEARISH

Zilliqa Blames 683M ZIL Theft on 7-Year Ledger Bug

The 683M ZIL figure gets the headline, but the seven-year survival of the bug inside a Ledger-signed application is the real read for any token still relying on native hardware-wallet signing.

Zilliqa published a post-mortem this week attributing the theft of 683,130,969.66 ZIL to a bug in its legacy Ledger application that discarded eight bytes of entropy during signature generation. The flaw forced the high 64 bits of every affected nonce to zero, allowing attackers to reconstruct private keys from as few as four already-published signatures. The disclosure quantifies an incident that ran from a March 4 first theft through July 20, when Zilliqa disabled legacy transactions roughly three and a half hours after the attacker's final on-chain move. KuCoin's anomalous-cold-wallet report on July 19 surfaced the active incident to the team.

Why it matters

The bug's longevity is the story. Zilliqa wrote the original affected implementation; the flaw then survived years of maintenance under Ledger without either party surfacing it. That gap matters for any token still relying on a Ledger app for native signing: a biased signing buffer does not show up in standard security audits the way a broken random-number generator does, and the four-signature exposure floor means the vulnerability can be exploited quietly against long-dormant wallets long before anyone notices.

Market impact

Zilliqa split the incident into two numbers that do not overlap. Sixty-six transactions drained 51 accounts, while 6,772 accounts had their private keys exposed. Recovery runs through migration to Zilliqa EVM, with the legacy chain retired, and no migration tool launch date has been announced pending an external security audit. The combined picture is the worst of both worlds for affected holders: a known exposure on thousands of wallets, a patched application that cannot help already-compromised keys, and an EVM exit that is not yet live.

Related tokens
$ZIL

Frequently asked questions

  1. How did the Zilliqa Ledger bug expose private keys?

    Zilliqa's legacy Ledger application generated 40 random bytes but copied the wrong 32 into its signing buffer, keeping eight bytes of zero padding and discarding eight bytes of entropy. That bias forced the high 64 bits of every affected nonce to zero, letting attackers rebuild private keys from as few as four…

  2. How much ZIL was stolen in the Zilliqa Ledger hack?

    The post-mortem quantifies the theft at 683,130,969.66 ZIL across 66 successful attack-window transactions that drained 51 accounts.

  3. How many wallets were affected by the Zilliqa Ledger bug?

    Zilliqa distinguishes two groups: 51 accounts were drained during the attack, while 6,772 accounts had their private keys exposed. The exposed-account total is a floor; additional compromised accounts may have produced theft transactions not yet proven.

  4. Why can't Zilliqa fix the Ledger bug to protect affected users?

    The application flaw has been patched, but already-published signatures cannot be withdrawn from the blockchain. Attackers can still reconstruct private keys from historical signatures, so the fix only protects new keys going forward.

  5. What is Zilliqa's recovery plan for affected holders?

    Zilliqa is migrating every legacy holder to Zilliqa EVM and retiring the legacy chain. The migration tool launch date has not been announced because timing depends on an external security audit, review of its findings, and any required remediation.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →