News
Public · Published
A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds
Zilliqa halted native token transfers after finding that five signatures created with the same private key can be used to reconstruct that key within seconds, exposing a critical security flaw.
Published:
Updated:
What happened
Zilliqa halted native token transfers after finding that five signatures created with the same private key can be used to reconstruct that key within seconds, exposing a critical security flaw.
Confirmed
Global impact / market context
If attackers can rebuild private keys, they can steal funds or forge transactions, threatening user assets and the platform’s reputation, which may lead to reduced usage and lower market confidence.
Confirmed
The issue affects Zilliqa, a blockchain platform that processes transactions using cryptographic signatures. A vulnerability in its ledger could undermine confidence in its network, prompting users to pause activity until a fix is deployed.
Confirmed
What to watch
- Whether Zilliqa releases a software patch to close the signature‑reconstruction vulnerability and how quickly it is adopted by validators. Analyst inference
- Potential migration of users and developers to alternative blockchains if confidence in Zilliqa’s security does not recover. Analyst inference
- Regulatory scrutiny or guidance on cryptographic standards that could arise from this bug, influencing broader blockchain security practices. Analyst inference