BTC $64,760.05 +1.76%
ETH $1,916.80 +1.20%
BNB $593.07 +4.42%
XRP $1.08 +1.77%
SOL $74.52 +1.76%
TRX $0.3288 +0.84%
DOGE $0.0704 +0.52%
ADA $0.1703 +4.30%
BCH $219.91 +4.50%
LINK $8.48 +2.40%
HYPE $54.79 -0.13%
AAVE $100.02 +1.24%
SUI $0.6996 +2.50%
XLM $0.1723 +0.50%
ZEC $471.51 +1.59%
BTC $64,760.05 +1.76%
ETH $1,916.80 +1.20%
BNB $593.07 +4.42%
XRP $1.08 +1.77%
SOL $74.52 +1.76%
TRX $0.3288 +0.84%
DOGE $0.0704 +0.52%
ADA $0.1703 +4.30%
BCH $219.91 +4.50%
LINK $8.48 +2.40%
HYPE $54.79 -0.13%
AAVE $100.02 +1.24%
SUI $0.6996 +2.50%
XLM $0.1723 +0.50%
ZEC $471.51 +1.59%

keys

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.

Polish cryptocurrency trading platform exposed for Ponzi scheme, former CEO disappears with 4,500 Bitcoin private keys

According to Politico, Poland's major cryptocurrency exchange Zondacrypto is facing a serious fraud investigation. Its former CEO went missing in 2022, taking with him the private keys to a cold wallet containing 4,500 bitcoins (currently worth over $340 million). The current CEO has admitted to being unable to access the wallet and has recently been reported to have fled to Israel. Prosecutors estimate potential losses for customers to be around $97 million.On-chain data shows that the bitcoin balance in the platform's hot wallet has plummeted by 99.7% since mid-2024, with users generally reporting difficulties in withdrawing funds. Polish Prime Minister Tusk estimates that up to 30,000 users may be affected.Tusk publicly accused the platform of being funded by Russian-linked money, used to finance opposition lawmakers to obstruct Poland's cryptocurrency regulatory legislation. He bluntly stated that this is a "Polish version of a Ponzi scheme" and criticized the president for vetoing the localization of the EU MiCA framework twice, making Poland a "paradise for scammers."The platform's board stated that they failed to obtain "verifiable information" from the missing CEO and have collectively resigned. The founder has been missing since 2022, and the previously mentioned "suspect kidnapping allegations" case is still under investigation. This incident is expected to prompt Poland and the EU to strengthen regulatory scrutiny of cryptocurrency exchanges.
app_icon
ChainCatcher Building the Web3 world with innovations.