Morning Edition · Saturday, July 25, 2026Published at 1:44 AM EDT · New York
A biased signing nonce in the Ledger app means about five signatures from one key are enough to rebuild that key using lattice-reduction mathematics within seconds. The network says exploitation began on July 19.

The layer-1 network Zilliqa has suspended native transactions after concluding that roughly five signatures produced by the same private key can be enough to reconstruct that key. The defect is not a smart-contract bug or a stolen seed phrase. It is a cryptographic implementation error inside the Ledger hardware-wallet app that signs Zilliqa's native (non-EVM) transactions.
The root cause is a biased signing nonce. For each signature the app generated 40 bytes of randomness, reduced the value modulo the secp256k1 curve order, then copied the wrong 32-byte window into the nonce. That mistake fixed the highest 64 bits of every nonce at zero, leaving each value below 2^192. Predictable structure in a signing nonce is the standard condition that lets an attacker apply lattice-reduction techniques and recover the underlying key. Zilliqa says every version of the app shipped between 2019 and 2026 carried the flaw, that it observed on-chain activity consistent with active exploitation on July 19, and that it confirmed the cause on July 21.
Speed now determines the outcome. Because a reconstructed key lets an attacker submit a competing transfer that executes before any ordinary rescue transaction, Zilliqa is building a migration path rather than telling users to simply move funds. The flaw was confined to the native signing path, and the exchange Upbit placed ZIL on a delisting review.
Framing the defect as a flaw in Ledger's signing app, rather than in Zilliqa's protocol, preserves confidence in the chain and shifts liability to the hardware-wallet vendor.
Part of a tracked trend
Implementation Bugs, Not Just Exploits, Threaten Custody
Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.
Start a discussion in Townsquare.
More from this edition
The technical flaw is independently confirmed (KuCoin reproduced key recovery, Upbit restricted ZIL), but the "active exploitation began July 19" claim rests on Zilliqa's reading of on-chain patterns, with no published tally of funds actually taken.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The exposed asset here is the trust premium of hardware wallets, which holders and custodians pay for on the assumption that a device never leaks key material. A deterministic-nonce failure defeats that assumption without any phishing or malware, and the same class of bug (weak or biased ECDSA nonces) has exposed keys before. The parties most exposed are self-custody users of niche signing paths and the wallet vendors whose firmware certifications are the product they sell.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · crypto.news · Unchained
Comments
0No comments yet.