Public AML

Zilliqa Cold Wallet Theft Linked to Ledger App Vulnerability

Zilliqa reported the theft of ZIL from a cold wallet of an exchange partner due to a vulnerability. The issue stemmed from the Zilliqa Ledger app, allowing private key recovery from on-chain Schnorr signatures.

Zilliqa announced that ZIL was stolen from a cold wallet belonging to one of its exchange partners. An investigation revealed that the root cause was a nonce-generation vulnerability in the Zilliqa Ledger app, which has been present since 2019. This vulnerability allowed for the recovery of private keys from on-chain Schnorr signatures after approximately five or more native transactions.

The incident was confirmed not to be related to the operations of the exchange itself. In response to the theft, native transactions have been suspended, and Zilliqa is coordinating a fix to address the vulnerability.

Sources

Share:XTelegramLinkedIn