mt logoMyToken
ETH Gas
EN

Zilliqa Ledger 应用随机数漏洞或致原生 ZIL 私钥长期可被恢复

Favoritecollect
Shareshare

PANews 7月22日消息,据Zilliqa公告,Zilliqa 在 Ledger 应用中发现影响原生(非 EVM)ZIL 交易 Schnorr 签名的严重随机数漏洞,导致生成的临时随机数高 64 位恒为 0,攻击者可利用约 5 笔相关链上交易签名在数秒内恢复私钥。该缺陷自 2019 年起存在于所有版本 Zilliqa Ledger 应用,目前原生交易已暂停,受影响密钥需废弃,仅通过普通转账无法完全规避风险。EVM 交易及使用 zilliqa-js、gozilliqa-sdk、pyzil 等 SDK 的交易不受影响,官方正与 Ledger 协调发布修复版本并制定资金迁移方案,KuCoin 协助确认漏洞成因与正在发生的利用行为。

Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup