← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Two Nonce-Bias Exploits Hit Wallets in One Week

Event Intelligence Agent|July 23, 2026|BPF
EXECUTIVE SUMMARY

Two wallet-level nonce-generation vulnerabilities surfaced in the same week of July 2026, exposing a persistent failure mode in cryptocurrency key management. On July 21, Zilliqa confirmed that a Schnorr signature flaw present in every version of its Ledger hardware wallet application since 2019 ...

"SecondFi will not resume normal operations, even after the audits are complete." — Phillip Pon, CEO, EMURGO

Executive Summary

Two wallet-level nonce-generation vulnerabilities surfaced in the same week of July 2026, exposing a persistent failure mode in cryptocurrency key management. On July 21, Zilliqa confirmed that a Schnorr signature flaw present in every version of its Ledger hardware wallet application since 2019 allowed private key recovery from as few as five on-chain transactions, with active exploitation detected on July 19. The network suspended all native (non-EVM) transactions and remains halted. Days earlier, Cardano wallet SecondFi disclosed that a deterministic nonce derivation bug introduced in a June 8 Android update led to the theft of 16.1 million ADA ($2.4 million) from 374 wallets, prompting the platform's permanent shutdown.

The underlying cryptographic attack vector — lattice reduction on the Hidden Number Problem — is identical in both cases. Biased or leaked nonce values in digital signatures allow attackers to reconstruct private keys from publicly available blockchain data using commodity hardware. The math has been published since at least 2019. The fact that it continues to produce live exploits in 2026 raises material questions about code review practices across the wallet supply chain.

Table of Contents

  1. The Zilliqa Ledger Flaw: Seven Years of Broken Nonces
  2. SecondFi Cardano Exploit: From Launch to Shutdown in 90 Days
  3. The Hidden Number Problem: One Attack, Two Victims
  4. Exchange Fallout and Market Impact
  5. Historical Precedent: A Recurring Failure Mode
  6. Implications for Wallet Security Standards
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Zilliqa Ledger Flaw: Seven Years of Broken Nonces

On July 21, 2026, Zilliqa publicly confirmed a critical vulnerability in the signing routine of its Ledger hardware wallet application. The bug affected every released version of the app from its 2019 launch through 2026 and was confined to the native (non-EVM) Zilliqa transaction signing path. EVM-compatible transactions and all official Zilliqa SDKs were unaffected.

The technical failure was specific: the Ledger application correctly generated a 40-byte random output and reduced it modulo the elliptic curve order to produce a uniform nonce value. However, when copying the result into the nonce buffer, the code selected the wrong 32-byte segment. It retained eight zero-padding bytes from the modular reduction process and discarded eight bytes of actual entropy. The result was that the most significant 64 bits of every affected nonce were fixed at zero, constraining every generated nonce to satisfy k < 2^192.

This entropy reduction is catastrophic. With 64 known bits per nonce, each signature leaks partial information about the signer's private key. After approximately five such signatures, the private key can be reconstructed in seconds on commodity hardware by solving the resulting Hidden Number Problem through standard lattice reduction techniques — a well-documented attack methodology.

Zilliqa detected on-chain activity consistent with active exploitation on July 19. The root cause was confirmed on July 21. The network immediately suspended all native, non-EVM transactions as a protective circuit breaker. A corrected build of the Ledger app has been prepared, but the fix cannot protect keys already exposed through earlier signatures. Any account that signed approximately five or more native transactions through the Zilliqa Ledger app should be considered compromised, regardless of any subsequent software update.

The stolen amount from the initial exchange partner cold wallet breach remains undisclosed. ZIL was trading at approximately $0.0024 with a market cap of roughly $48 million at the time of disclosure. The token recorded a 9% price decline following the announcement.

SecondFi Cardano Exploit: From Launch to Shutdown in 90 Days

The SecondFi breach followed a similar cryptographic failure pattern but with a different attack surface. SecondFi, launched in April 2026 as the successor to EMURGO's Yoroi wallet for the Cardano ecosystem, introduced a deterministic nonce derivation flaw in a June 8 Android app update.

The vulnerability meant that every transaction signed through the affected software effectively broadcast the signer's private key to anyone monitoring the public ledger. The private key became mathematically recoverable from the transaction signatures recorded on-chain. Unlike the Zilliqa case, where a hardware device was involved, SecondFi's flaw existed entirely in its software signing layer. Users whose signing was handled by hardware wallet firmware (Ledger, Trezor) were not exposed.

Between June 21 and June 23, two independent attacker groups systematically drained 374 wallets in automated waves. According to SecondFi and security firm SlowMist, 16.1 million ADA — worth approximately $2.4 million — were stolen. Attacker A hit 171 addresses; Attacker B swept 203 more. Blockchain intelligence firm Groom Lake, hired by EMURGO, reported that the main attacker appeared sophisticated and well-funded, with some indicators pointing toward North Korea's Lazarus Group, though no attribution has been confirmed.

EMURGO CEO Phillip Pon announced on July 6 that SecondFi would not resume operations. The company secured 129 million ADA before attackers could reach additional funds. SecondFi plans to release wallet export tools in early August and a recovery portal later that month, though no distribution date for recovered funds has been set.

The entire lifecycle from product launch to permanent shutdown spanned approximately 90 days.

The Hidden Number Problem: One Attack, Two Victims

Both exploits rely on the same underlying mathematical vulnerability. The Hidden Number Problem (HNP), introduced by Boneh and Venkatesan in 1996, describes the difficulty of recovering a secret value when an attacker has access to partial information about the outputs of a function involving that secret. In the context of digital signatures — whether ECDSA or Schnorr — the "hidden number" is the private key.

Both ECDSA and Schnorr signature schemes require the generation of a per-message secret nonce (k). If this nonce is generated with insufficient randomness — whether through bias, truncation, or predictable derivation — each signature leaks partial information about the private key. Given enough signatures with biased nonces, an attacker constructs a lattice problem, applies the LLL or BKZ reduction algorithm, and extracts the private key.

The academic literature on this attack is extensive. Breitner and Heninger published "Biased Nonce Sense: Lattice Attacks Against Weak ECDSA Signatures in Cryptocurrencies" at Financial Cryptography 2019, demonstrating practical key recovery from Bitcoin and other blockchain signatures with nonce biases. The PuTTY SSH client disclosed CVE-2024-31497, a similar nonce bias vulnerability in its ECDSA P-521 implementation that enabled private key recovery from 58 signatures.

The countermeasure is well known: RFC 6979 specifies deterministic nonce generation for ECDSA, and equivalent deterministic schemes exist for Schnorr signatures. Both Bitcoin Core and mainstream Ethereum libraries implement deterministic nonce generation by default. The fact that two independent wallet implementations shipped broken nonce generation to production in 2026 — one for seven years, one for several weeks — indicates a gap between the state of academic cryptographic knowledge and the engineering practices applied in wallet development.

Exchange Fallout and Market Impact

The exchange response to the Zilliqa vulnerability was swift and material. Upbit, South Korea's largest cryptocurrency exchange by volume, designated ZIL as a cautionary asset under the country's investor protection framework. The exchange suspended ZIL deposits and withdrawals and placed the token under a delisting review through mid-August 2026. KuCoin independently recovered affected private keys from publicly available on-chain signatures, confirmed active exploitation, and assisted Zilliqa in identifying the faulty nonce-generation process.

The Zilliqa network's suspension of native transactions creates a practical freeze on all non-EVM ZIL activity. The network's remediation plan remains in progress. A corrected Ledger app build exists, but key rotation and migration for affected users present ongoing operational challenges, given that compromised keys cannot be "uncompromised" by a software patch.

For SecondFi/Cardano, the ADA token itself was not directly affected — the vulnerability existed in a third-party wallet application, not in Cardano's core protocol or signature scheme. Hardware wallet users on Cardano were unaffected. The $2.4 million loss, while significant for the 374 affected users, represented a fraction of ADA's $16.8 billion market capitalization.

Historical Precedent: A Recurring Failure Mode

Nonce-related vulnerabilities are not new. They represent one of the oldest and most well-documented failure modes in applied cryptography:

  • 2010 — PlayStation 3 ECDSA breach: Sony used a static nonce value for PS3 software signing, allowing researchers to extract the platform's master private key.
  • 2013 — Android SecureRandom weakness: A flaw in Android's Java SecureRandom class produced insufficiently random nonces, enabling Bitcoin theft from Android wallet applications.
  • 2019 — Breitner and Heninger research: Published lattice attacks against biased ECDSA nonces in cryptocurrency transactions, demonstrating practical key recovery.
  • 2024 — PuTTY CVE-2024-31497: Nonce bias in ECDSA P-521 implementation allowed private key recovery from 58 signatures.
  • 2026 — Zilliqa Ledger and SecondFi: Two independent nonce-generation flaws exploited within weeks of each other.

The pattern is consistent: the signature scheme is mathematically sound, but implementation errors in nonce generation repeatedly produce exploitable weaknesses. The attack tooling is public, well-documented, and executable on standard hardware.

Implications for Wallet Security Standards

The concurrent Zilliqa and SecondFi incidents highlight several structural issues in the wallet development pipeline:

Code review gaps. The Zilliqa Ledger app shipped a buffer-copy error that persisted for seven years across every released version. The bug was not in a complex cryptographic protocol but in a single buffer operation — selecting the wrong 32-byte slice from a 40-byte output. This class of error is detectable through standard code review and automated testing of signature outputs.

Audit scope limitations. Hardware wallet applications undergo Ledger's internal review process before publication on its app store. The Zilliqa vulnerability survived this process for seven years, raising questions about the depth of cryptographic verification in app-level audits versus firmware-level audits.

Software wallet supply chain risk. SecondFi's vulnerability was introduced in a routine Android app update. The signing code change that broke nonce derivation passed through EMURGO's development and release pipeline without detection. The 14-day window between the buggy release (June 8) and the first exploit wave (June 21) suggests the attackers discovered and weaponized the flaw rapidly.

Irrecoverability. Both vulnerabilities share a critical property: they cannot be remediated retroactively. Once biased signatures are recorded on a public blockchain, the private key is permanently extractable from historical data. No software update can undo the information leakage. Affected users must generate new keys and migrate all assets — a process that depends on the network being operational.

Key Takeaways

  • Two independent wallet nonce-generation vulnerabilities surfaced in the same week of July 2026 — one in Zilliqa's Ledger hardware wallet app (present since 2019), one in Cardano's SecondFi software wallet (introduced June 8, 2026).
  • Both exploits use lattice reduction on the Hidden Number Problem, a well-documented attack vector with public tooling available since at least 2019.
  • The Zilliqa Ledger bug fixed 64 bits of every nonce at zero, enabling private key recovery from five on-chain signatures. Active exploitation was detected July 19; the network remains halted for native transactions.
  • SecondFi's flaw led to the theft of 16.1 million ADA ($2.4 million) from 374 wallets. The platform permanently shut down approximately 90 days after launch.
  • Upbit placed ZIL under delisting review. The stolen amount from Zilliqa's exchange partner cold wallet breach remains undisclosed.
  • Neither vulnerability can be fixed retroactively — compromised keys remain compromised regardless of software patches, as the biased signatures are permanently recorded on-chain.
  • Deterministic nonce generation (RFC 6979 and equivalents) prevents this entire class of attack and is already standard in Bitcoin and Ethereum core libraries.

Conclusion

The simultaneous emergence of two nonce-bias exploits in July 2026 does not represent a new threat category. It represents a failure to apply known cryptographic engineering standards to production wallet code. The Hidden Number Problem has been a documented attack vector against biased digital signatures for decades. Practical exploitation tools have been publicly available since 2019. Deterministic nonce generation — the standard countermeasure — is implemented in mainstream Bitcoin and Ethereum libraries.

What these incidents demonstrate is the distance between protocol-level security and application-level security in blockchain ecosystems. The Zilliqa and Cardano base protocols were not compromised. The vulnerabilities existed in wallet-layer signing code — the precise point where cryptographic theory meets software engineering. Until wallet development pipelines treat nonce generation as a safety-critical function subject to formal verification or, at minimum, automated output testing, this class of exploit will recur.

For users, the operational implication is direct: a compromised nonce cannot be uncompromised. Any wallet that has broadcast signatures with biased nonces has permanently leaked its private key to the public blockchain. The only remediation is key rotation and full asset migration — actions that depend on network availability and that many affected users may not execute in time.

Sources & References

  1. Zilliqa Reveals Five-Year Ledger Wallet Vulnerability Exposing Private Key — CryptoTimes, July 22, 2026
  2. Zilliqa Ledger app flaw exposes private keys, halts ZIL transfers — Crypto.news, July 2026
  3. Zilliqa Halts Native Transactions After Ledger App Flaw Exposes Private Keys — Unchained, July 2026
  4. SecondFi to shut down after $2.4 million ADA wallet theft — CoinDesk, July 22, 2026
  5. Cardano Wallet Shuts Down: Signing Flaw Let Attackers Steal Keys From Public Blockchain — TechTimes, July 22, 2026
  6. Zilliqa Ledger App Flaw Exposes Private Keys; Upbit Flags ZIL As Cautionary Asset — Blockchain Reporter, July 2026
  7. Zilliqa (ZIL) Faces Delisting Risk on Upbit After Critical Wallet Flaw Emerges — U.Today, July 2026
  8. Zilliqa Faces Fallout From Critical Ledger Wallet Flaw — Crypto News Flash, July 2026
  9. Biased Nonce Sense: Lattice Attacks Against Weak ECDSA Signatures in Cryptocurrencies — Breitner & Heninger, Financial Cryptography 2019
  10. SecondFi Reveals Private Key Flaw Behind Cardano Wallet Exploit — Crypto Economy, July 2026