Related News

Bitcoin Falls Below $90,000 As Vanguard Exec Struggles With Bitcoin Value 

Bitcoin Falls Below $90,000 As Vanguard Exec Struggles With Bitcoin Value 

December 12, 2025
India Tightens Crypto Rules: Selfie and Geo-Checks Required

India Tightens Crypto Rules: Selfie and Geo-Checks Required

January 12, 2026
Polymarket Sees Record $153M Daily Volume After Chainlink Integration

Polymarket Sees Record $153M Daily Volume After Chainlink Integration

April 10, 2026

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news

Related News

Bitcoin Falls Below $90,000 As Vanguard Exec Struggles With Bitcoin Value 

Bitcoin Falls Below $90,000 As Vanguard Exec Struggles With Bitcoin Value 

December 12, 2025
India Tightens Crypto Rules: Selfie and Geo-Checks Required

India Tightens Crypto Rules: Selfie and Geo-Checks Required

January 12, 2026
Polymarket Sees Record $153M Daily Volume After Chainlink Integration

Polymarket Sees Record $153M Daily Volume After Chainlink Integration

April 10, 2026

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news
WEMAPLE NEWS - Brand Partnerships
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news
No Result
View All Result
CONTRIBUTE
WEMAPLE NEWS - Brand Partnerships
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news
No Result
View All Result
WEMAPLE NEWS - Brand Partnerships
No Result
View All Result
Home Crypto

Zilliqa points to hardware wallet flaw discarding entropy to expose crypto keys, enabling 683M ZIL theft

WeMaple AI by WeMaple AI
August 24, 2026
in Crypto
0
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

A recent Zilliqa Ledger bug exposed at least 6,772 accounts, according to the post-mortem, and enabled the theft of 683,130,969.66 ZIL across 66 successful attack-window transactions. The disclosure turned an earlier unquantified security flaw into a measured loss and exposure record while, as of the same date, legacy transactions remained paused and holders faced an undated migration to Zilliqa EVM.

You might also like

Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid

Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes

Coinbase gives community banks a stablecoin bridge while supplying infrastructure underneath

The figures measure different parts of the incident. Zilliqa separates 51 drained accounts from the 6,772 accounts whose private keys were shown to be exposed. The post-mortem leaves the number of affected people unquantified.

The exposed-account total is a floor. The 683.13 million ZIL total is exact for the compromised accounts currently known, according to the post-mortem, and it could rise if investigators prove that additional compromised accounts produced theft transactions.

Related Reading

A 7 year Ledger bug lets attackers rebuild a private key from five signatures in seconds




Why four signatures matter

Zilliqa said the application generated 40 random bytes but copied the wrong 32 bytes into its signing buffer, retaining eight bytes of zero padding and discarding eight bytes of entropy. That forced the high 64 bits of every affected nonce to zero.

Four or more biased signatures produced by the legacy Ledger application for the same account could then allow an attacker to reconstruct its private key from public blockchain data in seconds on ordinary hardware, according to Zilliqa. Already-published signatures cannot be withdrawn, so correcting the application can protect new keys but cannot repair keys already exposed.

Related Reading

A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button




The bulk scan behind the published count required at least five native signatures in a single signer era. The mathematical exposure floor is four biased signatures. Accounts with exactly four signatures were therefore absent from the bulk population count. Zilliqa’s live per-address checker uses tighter parameters and reports four-signature cases, while re-running the wider scan under those parameters remains outstanding.

Zilliqa Ledger flaw infographic separating 683,130,969.66 ZIL of proven theft, 66 theft transactions, 51 drained accounts and 6,772 known exposed accounts, with the four-signature scan gap and March-to-August timeline.

Zilliqa’s historical reconstruction dated the first proven theft to March 4. KuCoin reported anomalous outgoing transactions from one of its cold wallets on July 19, roughly four and a half months later. On July 20, the attacker’s last transaction came at 09:19:09 UTC, and Zilliqa disabled legacy transactions around 12:59 UTC.

The post-mortem also split responsibility among the companies. Zilliqa said it wrote the original affected application implementation, while the flaw survived years of maintenance under Ledger without either party finding it. KuCoin’s report exposed the active incident.

The Zilliqa Ledger bug is limited to the application’s legacy, non-EVM signing path. Zilliqa EVM activity, recovery phrases, assets held on other blockchains through the same device, and listed software-wallet signing paths are outside the disclosed scope.

Related Reading

Why AI is now a more immediate threat to Bitcoin than quantum computers




Zilliqa’s Aug. 20 status update said recovery would use migration of every legacy holder to Zilliqa EVM, with the legacy side retired. It had not announced a migration-tool launch date because timing still depended on an external security audit, review of its findings and any required remediation. Asset tracing and exchange coordination were continuing.

The post Zilliqa points to hardware wallet flaw discarding entropy to expose crypto keys, enabling 683M ZIL theft appeared first on CryptoSlate.

Read Entire Article
Tags: CryptoCryptoslate
Share30Tweet19
WeMaple AI

WeMaple AI

Recommended For You

Hackers mint trillions in fake Bitcoin, but 15 BTC bridge recovery leaves liquidity providers unpaid

by WeMaple AI
September 13, 2026
0

The native bridge remains paused as a 20% bounty window closes Sep 13 and final accounting continues The post Hackers mint trillions in fake Bitcoin, but 15 BTC...

Read more

Audited DeFi protocols lost $885M to attacks that occurred completely outside their audit scopes

by WeMaple AI
September 13, 2026
0

The ack3-affiliated preprint found a 721% outside-scope share after excluding two H1 2026 outliers, while August incidents add operational context The post Audited DeFi protocols lost $885M to

Read more

Coinbase gives community banks a stablecoin bridge while supplying infrastructure underneath

by WeMaple AI
September 13, 2026
0

Banks retain the customer interface, while undisclosed pricing, data, compliance and settlement terms will determine who captures the value The post Coinbase gives community banks a stablecoin bridge

Read more

Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys

by WeMaple AI
September 13, 2026
0

The risk is limited to manually exposed APIs, and version 244 closes the standard public path The post Malicious bots are actively probing exposed Bitcoin payment servers to...

Read more

Senate Democrats To Meet Sunday Night On CLARITY Act

by WeMaple AI
September 13, 2026
0
Senate Democrats To Meet Sunday Night On CLARITY Act

The post Senate Democrats To Meet Sunday Night On CLARITY Act appeared first on Coinpedia Fintech News Senate Majority Leader Chuck Schumer is convening a Democratic caucus meeting...

Read more
Next Post
Latest tariffs will stop Canadian honey travelling south, beekeepers commission says

Latest tariffs will stop Canadian honey travelling south, beekeepers commission says

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Bitcoin Falls Below $90,000 As Vanguard Exec Struggles With Bitcoin Value 

Bitcoin Falls Below $90,000 As Vanguard Exec Struggles With Bitcoin Value 

December 12, 2025
India Tightens Crypto Rules: Selfie and Geo-Checks Required

India Tightens Crypto Rules: Selfie and Geo-Checks Required

January 12, 2026
Polymarket Sees Record $153M Daily Volume After Chainlink Integration

Polymarket Sees Record $153M Daily Volume After Chainlink Integration

April 10, 2026

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news
WEMAPLE NEWS – Brand Partnerships

Wemaple will be firmly committed to the public interest and democratic values.

CATEGORIES

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news

BROWSE BY TAG

AZO Clean Tech Bitcoinist Bitcoinmagazine Canada News CBC.ca Celebrity News Christian Post CoinPedia Corporate Knights Crypto Cryptoslate Faith Geothermal Golf Hockey Lifehacker Ludwig-van.com NcrOnline newsbtc Skateboarding tomsguide.com Utah news dispatch

© 2025 wemaple.canadiana.news - all rights reserved. YYC TECH CONSULTING.

No Result
View All Result
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news

© 2025 wemaple.canadiana.news - all rights reserved. YYC TECH CONSULTING.