BTC $65,603.78 +0.30%
ETH $1,899.31 -0.75%
BNB $570.04 +0.16%
XRP $1.11 -1.66%
SOL $76.08 -1.33%
TRX $0.3310 +0.58%
DOGE $0.0699 -3.24%
ADA $0.1678 -2.93%
BCH $212.40 -1.52%
LINK $8.52 +0.08%
HYPE $58.78 +0.51%
AAVE $96.32 -0.77%
SUI $0.7460 -3.08%
XLM $0.1842 +0.18%
ZEC $509.42 -0.92%
BTC $65,603.78 +0.30%
ETH $1,899.31 -0.75%
BNB $570.04 +0.16%
XRP $1.11 -1.66%
SOL $76.08 -1.33%
TRX $0.3310 +0.58%
DOGE $0.0699 -3.24%
ADA $0.1678 -2.93%
BCH $212.40 -1.52%
LINK $8.52 +0.08%
HYPE $58.78 +0.51%
AAVE $96.32 -0.77%
SUI $0.7460 -3.08%
XLM $0.1842 +0.18%
ZEC $509.42 -0.92%

ledger

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Ripple announced a quantum resistance roadmap, aiming to make XRP Ledger quantum-resistant by 2028

Ripple officially announced its quantum resistance roadmap, with the core goal of making the XRP Ledger (XRPL) quantum-resistant by 2028. The roadmap primarily addresses the potential attack mode of "harvest now, decrypt later," where attackers collect encrypted data now and wait for future quantum computers to mature before cracking it.The entire plan will be implemented in four phases:Phase 1: Q-Day Emergency Preparedness (Already Started). Establish a Q-Day emergency response mechanism. If the existing classical encryption system is suddenly compromised, the network will immediately stop accepting traditional public key signatures, forcing a migration to quantum-safe accounts. At the same time, explore asset ownership verification solutions based on Post-Quantum ZK-proofs, allowing existing account holders to safely recover funds in emergencies without exposing vulnerable keys.Phase 2: Risk Assessment and Algorithm Testing (First Half of 2026). Conduct a comprehensive assessment of the impact of post-quantum cryptography on the performance, storage, and bandwidth of the XRP Ledger network. Collaborate with Project Eleven to conduct validator-level testing and Devnet benchmarking, deploy NIST standardized ML-DSA quantum-safe signature schemes, and develop prototypes for post-quantum custodial wallets. Core engineer Denis Angell has already deployed ML-DSA signatures on XRPL's AlphaNet.Phase 3: Devnet Hybrid Integration (Second Half of 2026). Parallel integration of candidate post-quantum signature schemes with existing elliptic curve signatures on the developer network (Devnet), allowing developers to test performance and system impacts without affecting the mainnet. At the same time, explore post-quantum zero-knowledge proof primitives and homomorphic encryption technologies for Confidential Transfers to enhance the privacy and compliance capabilities of tokenized real-world assets on XRPL.Phase 4: Full Mainnet Upgrade (Target 2028). Submit a formal protocol amendment, which will be fully enabled on the mainnet after being approved by validator votes, to implement native post-quantum cryptography. Focus on production-ready optimization: throughput tuning, validator reliability assurance, and coordinated migration of the ecosystem, ensuring a complete transition without affecting network speed and settlement finality.

XRP Ledger introduces Boundless to enable public chains to achieve bank-level privacy and compliant transactions

XRP Ledger announced the integration of zero-knowledge infrastructure provider Boundless to support banks and asset management institutions in executing transactions on the public chain that balance privacy protection and compliance.According to reports, this solution can hide sensitive information such as transaction size, frequency, and counterparties, while still allowing regulatory agencies to conduct audits through selective disclosure and role-based access control, thus achieving a balance between privacy and compliance. This integration will support institutional scenarios such as cross-border B2B payments, fund and capital management, over-the-counter (OTC) trading, tokenized asset issuance, and on-chain trading and lending.Industry insiders believe that the contradiction between the transparency of public chains and the demand for privacy has always been a significant barrier to institutional adoption, and this solution aims to reduce the so-called "transparency tax." Meanwhile, competition in the privacy track continues to heat up. Technologies such as zero-knowledge proofs (ZK) and fully homomorphic encryption (FHE) are accelerating implementation, pushing privacy capabilities from optional features to underlying infrastructure. Data shows that the market size of tokenized assets has reached approximately $29.25 billion, with a monthly increase of about 7.9%.
app_icon
ChainCatcher Building the Web3 world with innovations.