Zilliqa’s Ledger app has been leaking users’ private keys for seven years.

Since 2019, the app contained a critical bug in its signature process. Instead of generating a fresh random nonce for every signature (as required for security), it copied the wrong bytes — leaving part of the nonce fixed at zero.That small, predictable flaw was enough. Every transaction you signed leaked a little more information about your private key. After roughly five signatures, an attacker could recover the full key in seconds on a regular laptop.The bug existed in every version of the ap

CryptoAlerta — análise de criptomoedas e mercado em tempo real