Zilliqa Hack
What happened
On July 22, 2026, Zilliqa disclosed a security incident affecting legacy, non-EVM transactions signed through its Ledger application. A biased Schnorr nonce exposed enough information in repeated signatures for attackers to reconstruct private keys; Zilliqa paused legacy transactions and published a migration and recovery plan.
The Zilliqa Ledger app copied a 32-byte signing nonce from the wrong offset in a 40-byte random value, retaining eight bytes of zero padding and discarding eight bytes of entropy. This biased the Schnorr nonce and made key recovery possible from public signatures.
How it happened
The Ledger app generated 40 random bytes but copied the wrong 32 bytes into the signing buffer, leaving the high 64 bits of every Schnorr nonce fixed at zero. Four or more affected signatures from one account could be used with public chain data to recover that account's private key and drain funds.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.