Polylog
← Trends

Implementation Bugs, Not Just Exploits, Threaten Custody

Cryptographic implementation errors in wallets and signers (biased nonces, reused randomness, faulty derivation) keep surfacing as a distinct custody risk alongside smart-contract exploits, eroding the assumption that certified hardware protects keys.

forming · confidence 40 · Emerging (watchlist) · tracking since July 25, 2026 · updated July 25, 2026

Why the conviction moved

  • Jul 25
    Strengthened +6

    Zilliqa halted native transfers after a biased signing nonce in its Ledger app let attackers rebuild private keys from ~5 signatures via lattice reduction, with exploitation starting July 19 (edition report). A live, actively-exploited nonce-bias bug in certified hardware directly validates that implementation errors, not just contract exploits, are a distinct custody risk.

Source trail

  • Supporting · July 25, 2026

    Zilliqa Halts Native Transfers After a Seven-Year Ledger Flaw Lets Attackers Rebuild Private Keys

    Zilliqa halted native transfers after a biased signing nonce in its Ledger app let attackers rebuild private keys from ~5 signatures via lattice reduction, with exploitation starting July 19 (edition report). A live, actively-exploited nonce-bias bug in certified hardware directly validates that implementation errors, not just contract exploits, are a distinct custody risk.

    CryptoSlate

Unlock full source trail, score history, and daily updates.

Unlock Trends

Affected regions & assets

RegionsGlobal