Zilliqa Announcement
前往频道在 Telegram
Official Zilliqa Announcement Channel Official Zilliqa chat https://t.me/zilliqachat
显示更多6 161
订阅者
-424 小时
-127 天
-9730 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
七月 '26
七月 '26
+34
在4个频道中
六月 '26
+12
在0个频道中
Get PRO
五月 '26
+20
在0个频道中
Get PRO
四月 '26
+8
在0个频道中
Get PRO
三月 '26
+11
在0个频道中
Get PRO
二月 '26
+17
在4个频道中
Get PRO
一月 '26
+13
在0个频道中
Get PRO
十二月 '25
+20
在2个频道中
Get PRO
十一月 '25
+26
在0个频道中
Get PRO
十月 '25
+24
在0个频道中
Get PRO
九月 '25
+17
在0个频道中
Get PRO
八月 '25
+36
在1个频道中
Get PRO
七月 '25
+33
在1个频道中
Get PRO
六月 '25
+27
在2个频道中
Get PRO
五月 '25
+28
在3个频道中
Get PRO
四月 '25
+29
在1个频道中
Get PRO
三月 '25
+22
在1个频道中
Get PRO
二月 '25
+26
在1个频道中
Get PRO
一月 '25
+43
在1个频道中
Get PRO
十二月 '24
+49
在3个频道中
Get PRO
十一月 '24
+27
在1个频道中
Get PRO
十月 '24
+26
在2个频道中
Get PRO
九月 '24
+764
在9个频道中
Get PRO
八月 '24
+28
在2个频道中
Get PRO
七月 '24
+19
在3个频道中
Get PRO
六月 '24
+49
在4个频道中
Get PRO
五月 '24
+62
在3个频道中
Get PRO
四月 '24
+54
在4个频道中
Get PRO
三月 '24
+95
在5个频道中
Get PRO
二月 '24
+41
在8个频道中
Get PRO
一月 '24
+49
在8个频道中
Get PRO
十二月 '23
+77
在7个频道中
Get PRO
十一月 '23
+28
在2个频道中
Get PRO
十月 '23
+23
在1个频道中
Get PRO
九月 '23
+20
在0个频道中
Get PRO
八月 '23
+26
在0个频道中
Get PRO
七月 '23
+45
在0个频道中
Get PRO
六月 '23
+25
在0个频道中
Get PRO
五月 '23
+40
在0个频道中
Get PRO
四月 '23
+93
在0个频道中
Get PRO
三月 '23
+46
在0个频道中
Get PRO
二月 '23
+53
在0个频道中
Get PRO
一月 '23
+75
在0个频道中
Get PRO
十二月 '22
+28
在0个频道中
Get PRO
十一月 '22
+39
在0个频道中
Get PRO
十月 '22
+40
在0个频道中
Get PRO
九月 '22
+60
在0个频道中
Get PRO
八月 '22
+67
在0个频道中
Get PRO
七月 '22
+71
在0个频道中
Get PRO
六月 '22
+56
在0个频道中
Get PRO
五月 '22
+87
在0个频道中
Get PRO
四月 '22
+699
在0个频道中
Get PRO
三月 '22
+443
在0个频道中
Get PRO
二月 '22
+43
在0个频道中
Get PRO
一月 '22
+97
在0个频道中
Get PRO
十二月 '21
+132
在0个频道中
Get PRO
十一月 '21
+119
在0个频道中
Get PRO
十月 '21
+235
在0个频道中
Get PRO
九月 '21
+258
在0个频道中
Get PRO
八月 '21
+219
在0个频道中
Get PRO
七月 '21
+209
在0个频道中
Get PRO
六月 '21
+360
在0个频道中
Get PRO
五月 '21
+838
在0个频道中
Get PRO
四月 '21
+804
在0个频道中
Get PRO
三月 '21
+895
在0个频道中
Get PRO
二月 '21
+642
在0个频道中
Get PRO
一月 '21
+451
在0个频道中
Get PRO
十二月 '20
+10 832
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 27 七月 | +4 | |||
| 26 七月 | 0 | |||
| 25 七月 | +1 | |||
| 24 七月 | +1 | |||
| 23 七月 | +5 | |||
| 22 七月 | +2 | |||
| 21 七月 | +4 | |||
| 20 七月 | +6 | |||
| 19 七月 | +1 | |||
| 18 七月 | 0 | |||
| 17 七月 | +2 | |||
| 16 七月 | 0 | |||
| 15 七月 | +1 | |||
| 14 七月 | +2 | |||
| 13 七月 | +2 | |||
| 12 七月 | +1 | |||
| 11 七月 | 0 | |||
| 10 七月 | 0 | |||
| 09 七月 | 0 | |||
| 08 七月 | 0 | |||
| 07 七月 | 0 | |||
| 06 七月 | +1 | |||
| 05 七月 | 0 | |||
| 04 七月 | 0 | |||
| 03 七月 | 0 | |||
| 02 七月 | +1 | |||
| 01 七月 | 0 |
频道帖子
We have published a dedicated Ledger Incident Hub with the latest confirmed information on the signing flaw affecting the Zilliqa Ledger application for Legacy accounts.
Legacy Zilliqa transactions remain paused as a precaution. Zilliqa EVM is not affected.
The hub explains:
• what happened
• who may be affected
• what is currently paused
• what action users should take
• how the recovery work is progressing
You do not need to take any action right now. The Zilliqa team will never contact you first or ask for your seed phrase, private key or recovery phrase.
Read the Incident Hub: We have published a dedicated Ledger Incident Hub with the latest confirmed information on the signing flaw affecting the Zilliqa Ledger application for Legacy accounts.
Legacy Zilliqa transactions remain paused as a precaution. Zilliqa 2 (EVM) is not affected.
The hub explains:
• what happened
• who may be affected
• what is currently paused
• what action users should take
• how the recovery work is progressing
You do not need to take any action right now. The Zilliqa team will never contact you first or ask for your seed phrase, private key or recovery phrase.
Read the Incident Hub:https://www.zilliqa.com/ledger-incident/
| 2 | Nonce-Generation Vulnerability in the Zilliqa Ledger App
A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated with a predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key using only publicly available on-chain data.
Protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalised. Users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action.
Impact
The vulnerability affects private keys used to sign native Zilliqa transactions with a Ledger device. Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should be considered compromised. Its private key can be reconstructed from signatures already recorded on-chain, regardless of any subsequent software update.
The issue is confined to the Ledger app’s native signing path. EVM transactions are unaffected. Zilliqa software development kits, including zilliqa-js, gozilliqa-sdk and pyzil, generate nonces correctly and are not affected.
Root cause
Zilliqa native transactions are authenticated using EC-Schnorr signatures over secp256k1. Each signature requires a fresh, uniformly random 256-bit ephemeral nonce, (k). The secrecy and full-width randomness of (k) are essential, as any systematic bias can allow the private key to be recovered.
The signing routine generated 40 bytes of randomness and reduced them modulo the curve order, correctly producing a uniform 256-bit value. However, when copying this value into the nonce buffer, the code copied the wrong 32 bytes of the 40-byte output. This retained the eight zero-padding bytes introduced by the reduction and discarded eight bytes of entropy.
As a result, the most significant 64 bits of every generated nonce were fixed at zero, meaning (k < 2^{192}).
A nonce with 64 known bits leaks information about the private key with each signature. With five or more affected signatures, the private key can be recovered in seconds using commodity hardware by solving the resulting Hidden Number Problem through lattice reduction - a well-documented technique for attacking biased-nonce signatures.
Because the affected transactions are permanently recorded on-chain, this exposure cannot be reversed by updating the signing application. The affected keys must be retired.
Timeline
2019-2026: The defect was present in every released version of the Zilliqa Ledger app across all supported devices.
19 July 2026: On-chain activity consistent with active exploitation was observed.
21 July 2026: The root cause was isolated to the app’s nonce-handling code and confirmed by reproducing the issue against on-chain signatures.
Ongoing: A corrected version of the app is being prepared in coordination with Ledger. Release details will be announced separately.
Remediation
As soon as the issue was identified, native (non-EVM) transactions were suspended as a protective measure. This has halted further draining of affected accounts while a solution is prepared.
Affected accounts cannot be secured through an ordinary transfer. Because their private keys can be derived from data already recorded on-chain, an attacker with access to the same key could attempt to front-run a legitimate transfer as soon as transactions resume. Advising users simply to move their funds would therefore be ineffective and potentially unsafe.
A corrected build of the Ledger app has been prepared, restoring full-width nonce generation and preventing further weakened signatures from being produced. However, this does not protect keys that have already been used to sign affected transactions. Those keys must ultimately be retired.
A coordinated remediation plan to secure affected balances is being finalised and will be published separately. Until then, users who have signed native Zilliqa transactions with a Ledger device should take no independent action and should rely solely on official Zilliqa channels for instructions.
Users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected.
Acknowledgments
KuCoin played a key role in pinpointing the root cause in the Zilliqa Ledger app nonce generation, recovered affected private keys from publicly available on-chain signatures, and confirmed ongoing exploitation.
KuCoin’s timely reporting and responsible collaboration enabled rapid protective measures, helping safeguard users, ecosystem participants, and the broader Zilliqa ecosystem while the remediation plan was being developed.
We sincerely appreciate the KuCoin team’s professionalism, technical expertise, and cooperation throughout this process. | 765 |
| 3 | As our investigation has progressed, we would like to clarify one important point:
At this stage, we have found no evidence that the incident was caused by the exchange’s wallet management or operational processes. We appreciate the exchange’s cooperation in identifying the issue quickly and assisting throughout the investigation.
The investigation has instead identified a technical issue affecting transaction signing in a specific set of legacy ZIL1 wallets. We are continuing to verify the precise root cause before publishing a detailed technical report.
We will share a full post-mortem, including technical findings and any recommended actions, as soon as the investigation is complete.
Thank you for your patience while we work to ensure the information we share is accurate. | 1 011 |
| 4 | We have been made aware of a security incident involving one of our exchange partners, in which ZIL was stolen from a cold wallet.
The incident is under active investigation, and we are working with the relevant parties to establish the root cause and full scope. As a precaution, all exchanges have been notified and asked to temporarily pause ZIL deposits and withdrawals to prevent the stolen funds from being moved or sold through centralised platforms.
We understand the community will have questions. We will share further updates as soon as we have verified information. Please rely only on official Zilliqa channels for updates. | 1 077 |
| 5 | A question institutional teams ask: why not just run a compliance layer over an existing settlement chain?
On a chain built to settle first, settlement is the state transition; permission would have to be built into the definition of a valid transaction, not added after it. You cannot retrofit that.
The new post works through the architecture, and through the two-hander it depends on: LTIN issues the identity, Zilliqa runs the check beside it. https://blog.zilliqa.com/mediation-defined/ | 1 149 |
| 6 | August 2022. A counterparty already on the sanctions list. The payment goes out in USDT - the issuer doesn't block on designation, so it confirms and settles like any other transfer. Send the same value in USDC and the token itself would have refused it; on a permissionless rail you don't get to choose what your counterparty holds.
Screening happens afterward: a disclosure filed, the transfer still standing. Enforcement that depends on which coin moved isn't enforcement.
The fix is a permission check before settlement - run beside the rail, not by it.
- Identity issued by LTIN
- checked by Zilliqa before a transaction settles
That is what this partnership is built for. | 1 164 |
| 7 | A new chapter, not a new pitch.
LTIN and Zilliqa first started building together at LTIN's launch last October; today it becomes a partnership, which creates a new category. LTIN issues the verifiable identity; Zilliqa runs the neutral check that confirms permission before a transaction settles, beside it, on any chain.
Follow along. https://www.ltin.li/insights/ltin-and-zilliqa-deepen-partnership-to-build-trustworthy-global-digital-infrastructure-as-a-public-good | 1 453 |
| 8 | The roadmap is live - and there's a blog post explaining the thinking behind it.
Short version: Institutional blockchain finance has always settled first, checked
compliance after. Zilliqa is built to run that check before - on any chain or
settlement rail. The roadmap sets out how we build that infrastructure from now
through 2027, phase by phase, each step tied to something we ship.
Read the blog: https://blog.zilliqa.com/compliance-before-settlement-the-zilliqa-roadmap/
Read the roadmap: https://zilliqa.com/roadmap
More to come later this year. For now - this is the direction, on the record.
Tell us what you think. | 1 606 |
| 9 | Protofire has completed a major upgrade across the Zilliqa Safe stack.
What's new for users?
- Better protection against scams and address poisoning attacks
- Faster loading and fewer delays thanks to backend and performance upgrades
- Export your transaction history to CSV
- Batch multiple transactions together, including existing transaction batches
- Improved WalletConnect experience when switching networks
- Safe account limit increased from 10 to 40
- Cleaner signing flow with clearer transaction status
- Automatic execution option when enough signatures have been collected
Behind the scenes, the infrastructure has also been upgraded to improve reliability, scalability, and security across the platform.
This release lays the groundwork for upcoming features including:
Spaces - shared workspaces for teams and organisations
Nested Safes - manage Safes within Safes with a dedicated interface
Built on the trusted Safe protocol, Zilliqa Safe continues to improve with stronger security, better usability, and a smoother overall experience.
Try now: https://safe.zilliqa.com/home | 1 530 |
| 10 | Zilliqa mainnet will undergo a scheduled upgrade with the release of v0.21.0, introducing improvements to performance, security, and validator infrastructure.
Key upgrades:
• State pruning for better storage efficiency
• RANDAO support for improved randomness in consensus
• Deposit contract upgrade (deposit_v8)
• Flexible checkpoint versioning for smoother recovery and upgrades
Upgrade timeline (mainnet):
• Deposit_v8 activation - Block 25,902,000 (~May 5, 08:37 UTC)
• RANDAO activation - Block 25,905,600 (~May 5, 09:49 UTC)
Validators and node operators have already been notified and have upgraded ahead of these block heights. If any validator has not upgraded yet, please do so at earliest.
Community: No action is required. Funds remain SAFU.
More details: https://github.com/Zilliqa/zq2/releases/tag/v0.21.0 | 1 240 |
