Zilliqa’s Ledger app has been leaking users’ private keys for seven years. Since 2019, the app contained a critical bug in its signature process. Instead of generating a fresh random nonce for every signature (as required for security), it copied the wrong bytes — leaving part of the nonce fixed at zero. That small, predictable flaw was enough. Every transaction you signed leaked a little more information about your private key. After roughly five signatures, an attacker could recover the full k
CryptoAlerta — análise de criptomoedas e mercado em tempo real