Ledger app bug exposed keys; 683.13M ZIL stolen
A Ledger application bug discarded signing entropy, exposing private keys and enabling theft of 683,130,969.66 ZIL from at least 6,772 accounts, Zilliqa’s post-mortem reports.
Zilliqa’s post-mortem identifies a Ledger application bug that discarded entropy in signatures and exposed private keys, enabling the theft of 683,130,969.66 ZIL across at least 6,772 exposed accounts and 66 confirmed attacker transactions.
The report explains the affected Ledger app generated 40 random bytes for signing but copied the wrong 32 bytes into the signing buffer. That left eight bytes of zero padding and removed eight bytes of entropy, forcing the high 64 bits of each affected nonce to zero and producing biased signatures.
When an account has four or more biased signatures, an attacker can reconstruct its private key from public blockchain data in seconds on ordinary hardware. Published signatures cannot be revoked, so correcting the application only protects new keys; already-exposed keys remain vulnerable.
Zilliqa’s reconstruction dated the first proven theft to March 4. A cryptocurrency exchange reported anomalous outgoing transactions from a cold wallet on July 19. The attacker’s final recorded transaction occurred on July 20 at 09:19:09 UTC. Zilliqa disabled legacy transactions later that day at about 12:59 UTC.
The post-mortem separates 51 accounts that were drained from the broader set of 6,772 accounts whose private keys were shown to be exposed. The 683.13 million ZIL figure is exact for the compromised accounts currently proven and could increase if investigators link further thefts to additional exposed accounts.
The bulk scan that produced the 6,772 total required at least five native signatures in a single signer era, even though the mathematical exposure floor is four biased signatures. Accounts with exactly four biased signatures were therefore omitted from that wider count. Zilliqa’s live per-address checker uses tighter parameters and reports four-signature cases; a re-run of the wider scan under those parameters is still pending.
The post-mortem assigns development responsibility for the original application to Zilliqa and notes the flaw persisted through years of maintenance under Ledger without detection. The vulnerability is limited to the legacy, non-EVM signing path of the Ledger application. Activity on Zilliqa EVM, recovery phrases, assets held on other blockchains through the same device, and listed software-wallet signing paths were outside the disclosed scope.
Zilliqa has paused legacy transactions and plans to migrate every legacy holder to Zilliqa EVM and retire the legacy signing path. The company has not set a migration-tool launch date; timing depends on an external security audit, review of findings and any required remediation. Technical fixes to the application will prevent future keys from being exposed in the same way, but published signatures and already-exposed keys cannot be repaired. Asset tracing and coordination with exchanges are ongoing.








