BTC $65,063.16 -0.90%
ETH $1,883.34 -2.33%
BNB $567.08 -0.56%
XRP $1.11 -2.37%
SOL $75.51 -2.55%
TRX $0.3309 +1.06%
DOGE $0.0697 -3.68%
ADA $0.1671 -3.95%
BCH $211.37 -2.26%
LINK $8.50 -1.40%
HYPE $58.62 -0.85%
AAVE $95.50 -1.72%
SUI $0.7378 -4.54%
XLM $0.1830 -1.01%
ZEC $508.23 -1.46%
BTC $65,063.16 -0.90%
ETH $1,883.34 -2.33%
BNB $567.08 -0.56%
XRP $1.11 -2.37%
SOL $75.51 -2.55%
TRX $0.3309 +1.06%
DOGE $0.0697 -3.68%
ADA $0.1671 -3.95%
BCH $211.37 -2.26%
LINK $8.50 -1.40%
HYPE $58.62 -0.85%
AAVE $95.50 -1.72%
SUI $0.7378 -4.54%
XLM $0.1830 -1.01%
ZEC $508.23 -1.46%

transaction

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

The Russian Financial Supervisory Authority will be authorized to monitor all cryptocurrency transactions, with those over 60,000 rubles required to be reported

According to Bits.media, a new draft bill submitted by the Russian government aims to grant the Financial Supervisory Authority the power to monitor all cryptocurrency transactions. For cryptocurrency transactions exceeding 60,000 rubles and foreign trade cryptocurrency transactions exceeding 1,000,000 rubles, the agency will collect complete information such as the full names or corporate names of the payer and payee, wallet addresses, actual addresses, birth dates, and taxpayer identification numbers. Transactions below 60,000 rubles only require the provision of names and wallet addresses.The bill also stipulates that the new limit for digital asset transactions by banks is 1% of the bank group's capital, and banks must hold corresponding funds to cover risks for the purchased cryptocurrencies. The central bank will be authorized to restrict or prohibit specific cryptocurrency operations when they threaten investor interests or may "undermine the stability of the financial system," with the scope extending from non-bank financial institutions to banks. The bill is expected to take effect simultaneously with the main cryptocurrency regulatory legislation, originally scheduled for implementation on July 1, but the review has been postponed. The first deputy governor recently stated that the relevant laws may take effect on September 1.
app_icon
ChainCatcher Building the Web3 world with innovations.