Zilliqa Ledger App’s Nonce Flaw Lets Attackers Recover Private Keys From Just Five On-Chain Transactions
A critical nonce bug in the Zilliqa Ledger app lets attackers recover private keys from just five on-chain transactions. ZIL dropped ~10% on the disclosure.
Zilliqa disclosed a critical vulnerability in its Ledger hardware wallet app that allows attackers to reconstruct users’ private keys from publicly available on-chain transaction data — a flaw that has been live since the app first launched and sent ZIL down roughly 10% on the news. The bug sits in the nonce-generation logic of the Zilliqa-specific Ledger app, not in Ledger’s core firmware. But that distinction offers little comfort to anyone who has signed native Zilliqa transactions from a Ledger device at any point in the app’s history.
At its core, this is a weak-nonce problem in the cryptographic signing process. When a Ledger device signs a Zilliqa transaction, the app generates a nonce — a random value that must be unique for every signature — which is then combined with the private key to produce the public signature. Weak nonces, or reused ones, and the private key becomes mathematically recoverable from the public signatures alone. According to BingX and WuBlockchain reporting, an attacker needs only approximately five native Zilliqa transactions broadcast from a Ledger device to reconstruct the private key. Five. Any user who has sent ZIL more than a handful of times from a Ledger is potentially exposed.
Zilliqa’s official disclosure, covered by Bitget and CoinTelegraph, confirmed that the attack vector requires only publicly available on-chain data. No physical access to the Ledger device is needed once enough transactions have been signed and broadcast. The signatures are already on-chain, visible to anyone, and the flaw means they leak enough information to derive the key that produced them. Researcher pcaversaccio, posting on X, said the vulnerability has been live since the Zilliqa Ledger app was first launched — meaning exposure may extend back years, not weeks. This is not a new product. The Zilliqa Ledger app has been the recommended hardware-wallet path for ZIL holders for multiple cycles, and anyone who used it during the 2021 bull market, during staking operations, or for routine transfers could have signatures sitting on-chain that are now retroactively exploitable.
The timing makes it worse. ZIL dropped approximately 10% following the disclosure, according to BingX. That sell pressure hit during an already soft market: total crypto market cap sits at $2,337.28 billion, down 0.31% over 24 hours, with the Fear & Greed Index at 31 — firmly in “Fear” territory. BBTC$66,028.00▼0.88% trades at $66,099, down 0.69% on the day; EETH$1,932.03▼0.32% at $1,934, down 0.19%. A 10% drop in a single token against that backdrop is a sharp move. It reflects more than routine volatility — it reflects the market pricing in the possibility that an unknown number of Zilliqa Ledger users hold keys that are, in effect, already compromised. They just haven’t been drained yet.
Upbit, one of South Korea’s largest exchanges, flagged the issue alongside Zilliqa’s disclosure, according to WuBlockchain on X. That matters. South Korean exchanges have historically been among the most aggressive in halting deposits and withdrawals when a token’s underlying security is questioned, and Upbit’s involvement signals the disclosure is being treated as an active infrastructure risk, not a theoretical edge case. And the broader picture around ZIL infrastructure was already under strain — a separate story noted that Zilliqa recently asked exchanges to pause ZIL transfers after a suspected cold wallet breach at a partner. The nonce flaw lands directly on top of that existing security crisis around ZIL’s custody and transfer rails.
Ledger’s architecture is sound. The device is designed to keep private keys offline and sign transactions inside a secure enclave — none of that changed. The flaw is in the Zilliqa-specific app layer that runs on top of it. But for affected users, that’s academic. A key recoverable from five public signatures is a key that can sign transactions, move funds, and drain wallets, regardless of where the bug technically resides. The practical question now is whether Zilliqa and Ledger can ship a patched app version before attackers begin systematically harvesting signatures from the chain, and whether exchanges will hold transfer pauses long enough for users to migrate funds to non-Ledger signing paths. Watch for a patched Zilliqa Ledger app release and further exchange actions on ZIL deposits and withdrawals in the coming days.