pinetwork

Zilliqa freezes ZIL transfers as 2019 Ledger breach exposes private keys

On Wednesday, Zilliqa froze its native $ZIL transactions. The blockchain had a flaw in its Ledger application dating back to 2019. The bug allowed attackers to reconstruct private keys from signatures already present on the blockchain. Anyone who signed a native $ZIL Transferring with a Ledger device is risky.

The vulnerability was confirmed by Zilliqa in a post $ZIL transactions. Holders who only use EVM-compatible tools and Zilliqa SDKs to transact $ZIL will not be affected.

32-byte copy bug broke signature randomness

A Schnorr signature requires a random number, which must be unique. This is called an occasional case. This must be secret and unpredictable for each signature. If randomness is weakened, the calculation that protects the private key fails.

Zilliqa said the signature routine extracted the wrong 32 bytes from a value of 40 bytes. This left zero for the first 64 bits of each occasion. Zilliqa described the result as “predictably weakened occasional ephemera.” Remove all that randomness and an attacker with about five or more such signatures could reconstruct the signer’s private key. All we need is public on-chain data, the team said.

The bug has existed since 2019. Any qualifying signatures released since then are fair game for the rebuild.

Zilliqa was crystal clear on the blast radius. Only native $ZIL Transactions signed on Ledger hardware are exposed. Nothing else is. EVM transactions are clear. And the SDKs are clear too. For now, Zilliqa has told everyone who signed a native contract $ZIL With a great book to look forward to. Do not move any funds, do not try to repair yourself, wait for official instructions.

Zilliqa said it had already taken protective measures to prevent further losses and was working on a repair plan. Ledger itself is working on a patched version of the Ledger app and the timeline will be announced at a later date.

KuCoin indicators operate as $ZIL takes a second shot

It wasn’t theoretical. Zilliqa said on July 19 that it had detected on-chain activity consistent with exploitation. On July 21, he found the root cause. It was made public on July 22. The incident adds to what has already been the most hacked quarter on record for crypto.

KuCoin was specifically credited by Zilliqa for the diagnosis. Zilliqa said KuCoin helped identify the occasional bug. As a demonstration, the exchange retrieved the affected private keys from the public signatures, confirming that the exploit was in use. The cooperation allowed Zilliqa to take protective measures and implement a broader solution, according to the project.

On July 20, just days before the Ledger disclosure, Zilliqa revealed that $ZIL had been stolen from a cold wallet of one of his exchange partners. This sent the token to a new all-time low of $0.002441. This also prompted Coinone and KuCoin to stop $ZIL Deposits and withdrawals, Cryptopolitan reported at the time.

Such thefts became a trend this year after an attacker embezzled $820,000 from privacy protocol Hinkal in early July. CEO Alexander Zahnd called for calm. He said he would make a full report.

Zilliqa did not specify whether the two events were linked. All week $ZIL was under pressure. $ZIL down 3.5% in the last 24 hours to $0.00244 according to CoinGecko data. $ZIL reached a high of around $0.2563 in May 2021.

Exit mobile version