Zilliqa Ledger App Vulnerability Exposes Users to Private Key Theft
A critical flaw in the Zilliqa Ledger app allows attackers to reconstruct users' private keys using onchain data. Users are urged to stop using the app until a fix is available.

A serious security vulnerability has been discovered in the Zilliqa Ledger app, enabling attackers to recover users' private keys. The flaw allows malicious actors to reconstruct private keys using publicly available onchain data, potentially leading to unauthorized access to users' funds.
The vulnerability was reported by security researchers, who highlighted that the issue stems from how the app handles certain cryptographic operations. The researchers noted that the flaw could be exploited by anyone with access to the victim's public address and transaction history. Zilliqa has acknowledged the issue and is working on a patch, but until then, users are advised to refrain from using the app.
This vulnerability poses a significant risk to users' security, as private keys are the cornerstone of blockchain security. If an attacker gains access to a user's private key, they can potentially steal all the funds associated with that address. Users are strongly recommended to transfer their Zilliqa holdings to a different, secure wallet until the issue is resolved.
For those affected, the immediate step is to stop using the Zilliqa Ledger app and move funds to a secure wallet. Keep an eye on official Zilliqa channels for updates on when the vulnerability has been patched and the app is safe to use again.