← Radar

Incident case file

Sign in to watch

Zilliqa — Ledger app Schnorr nonce-generation flaw (HNP private key recovery)

Incident date July 19, 2026

1 views

PausedZilliqa (nativenon-EVM)Cryptographic Flaw / Private Key ExposureCluster: ZILLIQA-NONCEFLAW-2026-07

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: MISSING — not publicly disclosed by Zilliqa or exchange partner

Funds moved to: MISSING — amount and destination not publicly disclosed. NOTE: amount_lost_usd set to 0 as placeholder — actual amount is unknown (Zilliqa and exchange partner deliberately withheld). ZIL stolen from exchange partner cold wallet (quasi-confirmed: KuCoin, based on Zilliqa Jul 22 acknowledgment tweet crediting @kucoincom). All native ZIL transactions suspended as protective measure. Zero-knowledge recovery path under development for affected accounts.
Vulnerable component: Zilliqa Ledger app (all versions 2019–2026). Root cause: signing routine generated 40 bytes of randomness, reduced modulo secp256k1 order, but copied wrong 32-byte segment into nonce buffer — retained 8 zero-padding bytes, discarding 8 bytes of entropy. Result: MSB 64 bits of every Schnorr nonce fixed at zero (k < 2^192). With ≥5 affected native signatures on-chain, private key recoverable in seconds via Hidden Number Problem lattice reduction. EVM transactions, zilli

Timeline: The signing flaw existed in every version of the Zilliqa Ledger application since its first release in 2019. The nonce generation routine allocated 40 bytes of randomness, correctly reduced them modulo the secp256k1 curve order to produce a 256-bit value, but then copied the wrong 32-byte segment into the nonce buffer — retaining 8 zero-padding bytes from the modular reduction and discarding 8 bytes of entropy. This fixed the 64 most significant bits of every nonce at zero (k < 2^192). With as few as 5 affected signatures available on-chain, an attacker can reconstruct the private key in seconds via lattice reduction (Hidden Number Problem). On July 19, 2026, on-chain activity consistent with active exploitation was observed. On July 20, Zilliqa disclosed a security incident involving an exchange partner's cold wallet and requested all exchanges to pause ZIL deposits and withdrawals. On July 21, the root cause was isolated to the Ledger app nonce-handling code and confirmed by reproducing key recovery against on-chain signatures — with KuCoin credited for this technical breakthrough. On July 22, Zilliqa published a full technical advisory. On July 24, Zilliqa published a dedicated Ledger Incident Hub (https://zilliqa.com/ledger-incident/) with user guidance; a zero-knowledge recovery path for affected accounts was under development. As of reporting, the amount stolen and the attacker identity remain undisclosed. All legacy (non-EVM) Zilliqa transactions remain suspended.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)