Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys
Zilliqa warned that a vulnerability in the Zilliqa Ledger app could let attackers recover users’ private keys from onchain data. The flaw produces predictably weakened signatures, making key recovery possible. Protective measures are in place, and a coordinated fix with Ledger is being prepared. Users who signed at least five native Zilliqa transactions with a Ledger device are considered compromised and should wait for further instructions. The alert follows Zilliqa’s earlier request that exchanges pause ZIL deposits and withdrawals after a security issue led to an undisclosed amount of ZIL being stolen from a cold wallet. A corrected app version is expected. Users interacting with ZIL through EVM-compatible tools were not affected. The ZIL price fell 1.5% over 24 hours and 17% over the past week.
