On Wednesday, the Zilliqa team announced via X that a critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions.
The vulnerability causes signatures to be generated with predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key using only publicly available on-chain data.
The team assured users that protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalised. Users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action.
The vulnerability affects private keys used to sign native Zilliqa transactions with a Ledger device. Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should be considered compromised. Its private key can be reconstructed from signatures already recorded on-chain, regardless of any subsequent software update.
The issue is confined to the Ledger app’s native signing path. EVM transactions are unaffected. Zilliqa software development kits, including zilliqa-js, gozilliqa-sdk and pyzil, generate nonces correctly and are not affected.
Zilliqa added that a corrected build of the Ledger app has been prepared, restoring full-width nonce generation and preventing further weakened signatures from being produced. However, this does not protect keys that have already been used to sign affected transactions. Those keys must ultimately be retired.
A coordinated remediation plan to secure affected balances is being finalised and will be published separately. Until then, users who have signed native Zilliqa transactions with a Ledger device should take no independent action and should rely solely on official Zilliqa channels for instructions.
Zilliqa (ZIL) is one of the world’s first blockchains being built on a sharded architecture and features smart contracts written in the platform’s proprietary programming language: Scilla.
It is a public, permissionless blockchain that is designed to offer high throughput with the ability to complete thousands of transactions per second. It seeks to solve the issue of blockchain scalability and speed by employing sharding as a second-layer scaling solution. The platform is home to many decentralized applications, and as of October 2020, it also allows for staking and yield farming.
Zilliqa claims to be the world's first public blockchain to rely entirely on a sharded network. This allows it to achieve high throughput and a high rate of transactions per second, which it says solves the scalability issue. Because each shard processes transactions individually, as the network grows and the number of shards increases, the number of transactions that can be processed per second also increases. As well, records are immediately added to the Zilliqa blockchain after being processed, meaning that no additional time for confirmation is required.
Zilliqa seeks to become the blockchain of choice for large-scale enterprise use, including among the advertising, gaming, entertainment, and financial services and payments industries. In its 2018 position paper, its team states that the platform "aims to rival traditional centralized payment methods such as VISA and MasterCard."
ZIL is trading at $0.002505, down 0.6% in the last 24 hours.
Nikolas Sargeant