A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
Zilliqa suspended native, non-EVM transactions after finding a critical flaw in the Zilliqa Ledger app’s Schnorr signing code. The bug affected every app version released from 2019 to 2026 and caused nonce generation to lose 8 bytes of entropy, leaving signatures vulnerable to lattice attacks. Zilliqa said roughly five signatures from the same private key may be enough to reconstruct that key in seconds on commodity hardware. The issue was detected as active exploitation on July 19 and confirmed on July 21. Zilliqa did not disclose affected addresses or losses. Because the weak signatures are already on-chain, updating the app cannot fix exposed keys; accounts with about five or more native Ledger-signed transactions should be treated as compromised and the keys retired. KuCoin helped verify the issue and trace it to the app’s nonce-generation code. Zilliqa paused native transfers to prevent further draining and warned users not to act until official migration instructions are released. EVM transactions and the official SDK nonce paths are unaffected.
