MultiversX Tracker is Live!

A crypto wallet app LEAKED people's private keys for SEVEN years, and nobody noticed until last week.

All Cryptocurrencies

by COINS NEWS 20 Views

Zilliqa’s Ledger app has been leaking users’ private keys for seven years.

Since 2019, the app contained a critical bug in its signature process. Instead of generating a fresh random nonce for every signature (as required for security), it copied the wrong bytes — leaving part of the nonce fixed at zero.

That small, predictable flaw was enough. Every transaction you signed leaked a little more information about your private key. After roughly five signatures, an attacker could recover the full key in seconds on a regular laptop.

The bug existed in every version of the app and went completely unnoticed until last week, when wallets started getting drained.

The damage is permanent. Those flawed signatures are immutably recorded on the blockchain. Affected users can’t safely move their funds — the attacker already has the key and will almost certainly win any race.

A hardware wallet app quietly exposed private keys in public for nearly a decade.

submitted by /u/b4basit
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments