BTC $65,328.47 -0.26%
ETH $1,890.43 -1.51%
BNB $568.13 -0.32%
XRP $1.11 -1.92%
SOL $75.81 -1.85%
TRX $0.3311 +1.08%
DOGE $0.0698 -3.36%
ADA $0.1676 -3.16%
BCH $211.98 -2.15%
LINK $8.52 -0.24%
HYPE $58.85 -0.02%
AAVE $96.05 -0.92%
SUI $0.7423 -3.74%
XLM $0.1837 -0.18%
ZEC $510.58 -1.07%
BTC $65,328.47 -0.26%
ETH $1,890.43 -1.51%
BNB $568.13 -0.32%
XRP $1.11 -1.92%
SOL $75.81 -1.85%
TRX $0.3311 +1.08%
DOGE $0.0698 -3.36%
ADA $0.1676 -3.16%
BCH $211.98 -2.15%
LINK $8.52 -0.24%
HYPE $58.85 -0.02%
AAVE $96.05 -0.92%
SUI $0.7423 -3.74%
XLM $0.1837 -0.18%
ZEC $510.58 -1.07%

vulnerability

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Summer.fi Lazy Summer attack is not a contract vulnerability, but rather an exploitation of the NAV mechanism

Summer.fi released an analysis report on the Lazy Summer Protocol USDC treasury attack incident. The attacker manipulated the prices of two USDC treasury shares in a single atomic transaction, extracting approximately $6.04 million of depositor funds. The core of the attack lies in the calculation method of the treasury's net asset value (NAV).The attacker donated tokens that still retained the old valuation to a Silo Ark that had been suspended after the incident in November 2025 but had not yet been completely removed, resulting in an inflated total asset value of approximately 9.5%, raising the share price, which was then redeemed at an inflated price and withdrawn from the treasury's actual liquidity. The report emphasizes that this attack was not due to a contract code vulnerability, but rather a missing link in the treasury's offline process—the deposit limit for that Ark had been set to zero, yet it was still counted in the NAV of active assets.The attacker premeditatedly accumulated the required tokens three months in advance through multiple wallets and transferred part of the profits via Tornado Cash. After the incident, Guardian Multisig has suspended all on-chain treasuries and set the deposit limit to zero. The Lazy Summer DAO will discuss compensation plans for affected users and the treasury restart plan in the coming days.

Secret Network lost 4.67 million dollars due to a cross-chain vulnerability, and the attack went undetected for seven days

The blockchain research organization Common Prefix disclosed that on June 10, hackers exploited a vulnerability in the Secret Network and Axelar cross-chain bridge contract to forge deposits and mint uncollateralized tokens, subsequently cashing out approximately $4.67 million.The attack went undetected for seven days until a normal cross-chain transfer failed due to insufficient funds in the escrow account on June 17, revealing the anomaly. The root of the vulnerability lies in the fact that when the contract changed from an escrow model to a minting model, it deleted two key functions responsible for verifying the source of transfers, and it had never undergone an external audit since its deployment in early 2023. Secret Network pointed out that the Axelar bridging infrastructure failed to trigger any effective anomaly monitoring or emergency pause mechanism before the assets were stolen on a large scale.The stolen funds were routed through Osmosis to Ethereum and exchanged for ETH on CoW Protocol, then dispersed into exchanges such as KuCoin, ChangeNow, and HitBTC. Currently, approximately $672,000 remains in the attackers' Axelar wallet. Secret Network has requested Axelar to freeze that address, but the request was denied. Axelar emphasized that its core protocol was never affected, and the exploited contract was not developed or maintained by Axelar. Currently, Axelar has disabled the related cross-chain connections and stated that it is coordinating follow-up actions with exchanges and law enforcement agencies.

Axelar responds to security incident: Axelar and IBC are unaffected, the vulnerability originates from a third-party token contract's "infinite minting" issue

The cross-chain protocol Axelar Network released a statement regarding the recent security incident related to Secret Network, stating that there is a misunderstanding within the community about the event. Both Axelar and the Inter-Blockchain Communication Protocol (IBC) were not attacked or compromised. The affected token smart contracts were neither developed, deployed, nor maintained by Axelar, and Axelar's firewall mechanism also prevented the impact from spreading to other chains.It is reported that the exploited contract is a forked version based on CW20-ICS20, but the developers removed two core security checks, resulting in an "infinite minting" vulnerability. By deleting the verification mechanisms originally used to prevent such issues, this fork altered the original trust model of the contract and did not undergo a new security audit.Axelar Network explained that anyone can deploy contracts for cross-chain asset wrapping through IBC, and similar contracts have also been used to wrap tokens from other chains into Secret Network. However, the Secret side fork version in this incident has vulnerabilities due to the removal of key security checks. This incident is not a unique logical flaw, nor is it an issue with the IBC protocol itself, but rather a security risk introduced by modifications to third-party contracts.
app_icon
ChainCatcher Building the Web3 world with innovations.