暗号資産購入
マーケット
スポット
先物
金融
特別企画
さらに
reward-center新規登録ゾーン
ホーム速報詳細
Zilliqa Ledger App Exposes Severe Vulnerability, Signing 5 Native Transactions Could Leak Private Key
  • ZIL0%

BlockBeats News, July 22nd, Zilliqa announced that its hardware wallet manufacturer Ledger has a severe random number generation vulnerability in its application, affecting Schnorr signature for native non-EVM Zilliqa transactions. An attacker can recover the signer's private key from a biased temporary random number using only on-chain data.

Any account that has signed and broadcasted around 5 or more native transactions through the Zilliqa Ledger app should be considered compromised. Since the affected signatures are permanently recorded on the blockchain, subsequent app updates cannot eliminate the risk, and the compromised private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, pyzil are not affected.

The vulnerability originated from selecting the wrong 32 bytes when deriving the application's replicated random number, retaining 8 bytes as zero-padding and losing 8 bytes of entropy, resulting in the top 64 bits of each random number being fixed at zero. An attacker can recover the private key within seconds using ordinary hardware with 5 or more affected signatures. Zilliqa observed suspected active exploitation on July 19th and confirmed the root cause on July 21st.

Zilliqa has halted native transactions to prevent further fund losses and is working with Ledger on a patched version of the application. However, the patch cannot protect exposed keys, and affected users should not transfer assets on their own at the moment but wait for the official announcement of a coordinated remediation plan.

ソース:BlockBeats

免責事項:現在のコンテンツは第三者の視点に基づくもの、または第三者の視点からAIが直接翻訳したものです。CoinExはコンテンツの信頼性、正確性、独創性を保証するものではなく、CoinExからの投資アドバイスを構成するものではありません。暗号資産の価格変動は急激に変動します。潜在的なリスクにご注意ください。

検索上位
  • コインリスト
    価格
    24時間価格変動