Zilliqa halts native transactions due to a Ledger app vulnerability allowing reconstruction of private keys from signatures.
Zilliqa has recently suspended native transactions after discovering a significant vulnerability in its Ledger app. This flaw allows attackers to reconstruct transfers-challenge-legal-claims-to-dormant-wallets/">private keys from a handful of signatures, creating serious security risks for users of the network.
The vulnerability primarily impacts Schnorr signatures generated for native, non-EVM transactions through the Zilliqa Ledger app. Affected users can be severely compromised, as the flaw has persisted since the app’s release in 2019. With this issue now made public, Zilliqa is racing against time to patch the vulnerability and safeguard its users’ assets.
On July 19, Zilliqa detected suspicious on-chain activities suggesting active exploitation of the vulnerability. After confirming the root cause on July 21, the network moved swiftly to suspend native transactions, emphasizing that a corrective action plan had become critical.
The core of the problem lies in how the Ledger app generates an ephemeral nonce for each signature. During the signing process, the app was supposed to create 40 bytes of randomness, reduce this modulo the secp256k1 curve order, and then copy a 32-byte range into the nonce buffer. However, an error in this process led to eight bytes of actual entropy being discarded while retaining eight zero-padding bytes.
This oversight fixed the highest 64 bits of the nonce value at zero, ultimately leading to predictable nonce values below 2192. It means that with just five affected signatures from the same private key, an attacker can exploit lattice-reduction techniques to reconstruct the private key in a matter of seconds.
According to Zilliqa, the exposure of the private key places any account that has executed approximately five or more native transactions through the Zilliqa Ledger app at risk of being compromised. Since the signatures remain permanently on-chain, the information cannot simply be erased by updating the app. Affected users must take precautionary measures to protect their funds, including considering retirement of their private keys.
The nature of the broader implications is concerning. An ordinary transfer designed to rescue assets could be subject to front-running by anyone who has reconstructed the affected key. Essentially, an attacker could anticipate and intercept an asset transfer, thus thwarting efforts by legitimate users to reclaim their funds.
Zilliqa acknowledges the precarious position users find themselves in. The network is developing a coordinated migration plan to help facilitate the safe movement of assets while minimizing the risk of front-running by malicious actors.
In a move that emphasizes collaborative efforts in the crypto space, Zilliqa credited KuCoin with reporting the bug. The exchange played a crucial role in confirming the vulnerability and tracking its origin back to the nonce-generation code in the Ledger app.
Through their investigation, KuCoin was able to assist affected users by pointing out transaction anomalies linked directly with compromised private keys. This proactive approach highlights the interdependence within the crypto community, where exchanges and networks work together to safeguard users in the face of security vulnerabilities.
The combined expertise of Zilliqa and KuCoin is likely to yield a robust recovery plan that will restore confidence among users. However, the network is urging caution and has advised that those who have interacted with the Ledger app should await official guidance before taking further action.
Zilliqa’s suspension of native transactions is a protective measure aimed at safeguarding users from further compromise. As the network finalizes its coordinated remediation plan, it must address the twin challenges of enabling legitimate users to migrate their assets while minimizing the risk of front-running by attackers.
The upcoming update to the Ledger app will restore full-width nonce generation, preventing similar issues from exposing sensitive information in the future. However, it’s important to highlight that while this fix may secure future signatures, it will not rectify the vulnerabilities associated with signatures already recorded on-chain.
As of the latest updates, Zilliqa has not provided a reopening date for native transactions nor detailed its migration procedure. Users are left in a state of uncertainty as they await further communication from the network regarding their assets.
This incident underscores a critical lesson in cryptocurrency security. The community must remain vigilant, ensuring that platforms take proactive measures to safeguard their applications and, ultimately, user assets. As the crypto landscape evolves, the need for improved security practices becomes even more crucial.
The scenario faced by Zilliqa and its users serves as a sobering reminder of the vulnerabilities inherent in crypto technology. As developers and networks strive to enhance security measures, user diligence and collaboration across platforms will play an essential role in preserving trust in the ecosystem.
As Zilliqa prepares to unveil a resolution, it’s imperative for users to stay informed and to act wisely to protect their digital assets. The community will be watching closely to see how Zilliqa navigates this challenge and implements the changes needed to restore security and functionality to its native transactions.