The video provides a lucid breakdown of how implementation flaws can compromise keys without breaching the hardware's secure element. It serves as a sobering reminder that even the most robust security architecture is ultimately at the mercy of its weakest application-layer code.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Ledger HACKED? The Truth About the Zilliqa App Bug
Added:Hey guys, CryptoDad here again. And if you've been hearing stories that Ledger devices have been leaking private keys for 7 years, I want to stop you right there. That is not what happened. This was not a failure of Ledger hardware. It was not a flaw in the Ledger wallet software. And if you own a Ledger device, this does not mean that your Bitcoin, Ethereum, XRP, Solana, Cardano, or any other cryptocurrencies are suddenly at risk. So, before you throw away your hardware device, let me cut through the hype and explain to you exactly what happened.
Now, this particular flaw only affected the Zilqua app that runs on your Ledger device. And it only affected native Zilqua transactions. This bug was so subtle that it remained undetected for 7 years until someone finally found it by analyzing signatures recorded on the blockchain. Now, before we talk about the bug itself, let's talk a little bit about how Ledger devices work. A lot of people think that it's just one giant crypto wallet. It is not. Your Ledger device is more like a giant secure computer that runs many secure blockchain apps within it. And they are all siloed. So, there's a Bitcoin app, an Ethereum app, an XRP app, a Solana app, a Cardano app, and in today's case, there's a Zilqua app that had a very subtle flaw that was recently discovered. So, each of these siloed apps understand the rules of its own blockchain and prepare transactions for signature on the secure element chip of the device. Some of those applications like Bitcoin and Ethereum are developed primarily by Ledger software engineers.
Other medium-sized chains like Cardano, Solana, and XRP are developed in close coordination with the Ledger developers.
Other smaller blockchains like Zilqua develop their own apps using the Ledger SDK and then are submitted to Ledger for review, testing, and distribution. And that's an important distinction because the vulnerability that we're talking about today only involves the Zilqua app, not the Ledger OS or the secure element chip on the Ledger device.
Also, keep in mind that each of these apps generates its own separate private key derived from the master private key of the Ledger device. So, the Zilqua app was generating its own separate private key only for Zilqua. It had nothing to do with the main private key or any of the other private keys for any of the other crypto apps. So, what went wrong here?
Well, anytime you sign a cryptocurrency transaction, the private key of that transaction is not simply stamped onto the blockchain. Instead, the code that handles the signing process generates a random number that is only used for that one transaction. Cryptographers call this a nonce. Think of it as a one-time secret ingredient that is mixed in to every digital signature. The security of every digital signature depends on that nonce being completely random and unpredictable. According to Zilliqa's own disclosures, the app generated that number correctly. When the Zilliqa application copied that nonce into memory to prepare for signing, it accidentally copied some of the wrong bytes.
>> [snorts] >> As a result, part of a 256-number that should have always been completely random, a small piece of it was always zeros.
So, the signatures still worked, the transactions were accepted, nothing crashed, no warnings appeared.
Everything looked completely normal.
That's why this bug survived since 2019 until only recently. So, why is this dangerous? Why is this cryptographic nonce that contains some zeros causing problems in the code? So, each time someone signed a ZIL transaction, the weakened signature was leaking a tiny amount of mathematical information every time. One transaction wasn't enough. Two weren't enough. But, after several signatures, five according to researchers, there was enough information in those public signatures for an attacker to combine them and use well-known cryptographic techniques to determine the private key. Mind you, this is only the private key of the Zilliqa blockchain that we're talking about, not any other private keys managed by the device. Notice what didn't happen. The attacker never hacked the Ledger device. They never extracted the private key from the secure element.
They never needed the recovery phrase of the device. They simply analyzed information that had been publicly published to the the ZIL blockchain. So, as I mentioned earlier, this only affects the Zil blockchain. So, I'm going to explain why.
So, suppose your ledger contains cryptocurrencies like Bitcoin, Ethereum, Solana, XRP, and maybe some native Zil as well. Only the native Zil account is affected. And if you are not a holder of Zil, and you have never downloaded the Zil app on your device, then this exploit does not concern you in any way or form. Bitcoin, Ethereum, and other cryptocurrency use a completely different signing implementation in their code. Even EVM-compatible transactions on the Zil coin network were not affected by this because they use a completely different signing implementation. So, what does this mean for Ledger hardware wallet owners? For the overwhelming majority of Ledger users, this incident changes nothing.
Your Ledger hardware isn't broken. It behaved exactly the way it was supposed to. The secure element wasn't compromised. Ledger wallet software wasn't compromised. This was an extremely subtle cryptographic implementation bug running within one blockchain app running on the device.
The lesson here isn't that hardware devices can't be trusted. The lesson is that modern cryptography is very unforgiving. Sometimes a mistake that's literally just a few incorrect bytes of code can run undetected for years before someone discovers it. This is also the reason why you should not be afraid of updates. Updates fix and patch these types of vulnerabilities moving forward.
I'm curious what you think. Are you surprised to learn that one blockchain app running on the Ledger device could have a vulnerability like this and not affect any of the other apps that were running on the device?
If so, let me know down in the comments.
If you like this video, give it a thumbs up. If you'd like to subscribe to my channel, I would appreciate it. When you subscribe, there's a little bell that you can click that will allow you to be alerted whenever I post new content.
Once again, thanks for joining me and hope to see you again soon.
Related Videos

Multi Vendor Multisig w/ Seed Signer, Hodl Dee & QnA
BitcoinMagazine
985 views•2024-09-05

Oasis Week in Review: Latest blog articles, workshops and more
OasisFoundation
135 views•2024-10-18

Kaspa: How ZK Turn Blockchains Into Settlement Layers (Part II)
cxc
1K views•2025-12-19

以言會友 EP13|當比特幣屢破紀錄 區塊鏈技術能帶來什麼?
dotdotnews
293K views•2021-01-05

Soroban Development: Ecosystem Growth, and the Rise of 70+ Smart Contract Projects
SorobanOfficial
1K views•2023-07-19

Balaji Srinivasan I The Fiat Crisis | Pragma Tokyo 2023
ETHGlobal
37K views•2023-05-06

$22 million NFT scammers arrested (insider evidence)
coffeezillaextras
806K views•2025-02-03

SYMMETRICAL TRIANGLE HOLDS THE KEY TO NEXT MOVE" DON'T IGNORE
xrpfuturemillionaire
800 views•2026-03-15
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23