Historical Bug Uncovered in Zilliqa's Ledger Integration, Prompting Transaction Shutdown
The Zilliqa blockchain project is addressing a significant security concern. A critical vulnerability has been identified within its application designed for Ledger hardware wallets, with evidence suggesting the flaw may have been present since 2019.
Nature of the Flaw and Associated Risks
This vulnerability potentially allows malicious actors to recover the private keys used to sign native ZIL transactions. Private key compromise represents a severe threat, as it grants complete control over the associated crypto assets—a type of attack known as key recovery.
To safeguard user funds, Zilliqa has proactively disabled all native ZIL transaction functionality through the affected Ledger app. This temporary suspension is a containment measure while a permanent fix is developed.
Scope of Impact and Mitigation Efforts
The impact of this issue is contained to a specific use case:
- Affected: Users conducting native ZIL transactions via the Ledger hardware wallet and its Zilliqa application.
- Not Affected: All transactions and smart contract interactions on Zilliqa's EVM-compatible layer (Scilla-EVM). These operations continue normally.
Zilliqa's technical teams are now working closely with relevant partners to formulate and deploy a coordinated patch. This process may involve updates from both Zilliqa and Ledger.
Users managing ZIL assets with Ledger devices should refrain from using the compromised application for any actions until an official security update and announcement are released. Monitoring Zilliqa's official communication channels for further instructions is strongly advised.