BTC $65,569.30 -1.21%
ETH $1,920.25 -0.73%
BNB $570.05 -1.10%
XRP $1.12 -0.39%
SOL $77.20 -1.41%
TRX $0.3296 +0.28%
DOGE $0.0723 -1.33%
ADA $0.1724 -1.68%
BCH $220.89 -1.86%
LINK $8.60 -1.27%
HYPE $58.27 -6.88%
AAVE $96.45 +2.31%
SUI $0.7612 -0.93%
XLM $0.1881 -3.47%
ZEC $514.49 -5.61%
BTC $65,569.30 -1.21%
ETH $1,920.25 -0.73%
BNB $570.05 -1.10%
XRP $1.12 -0.39%
SOL $77.20 -1.41%
TRX $0.3296 +0.28%
DOGE $0.0723 -1.33%
ADA $0.1724 -1.68%
BCH $220.89 -1.86%
LINK $8.60 -1.27%
HYPE $58.27 -6.88%
AAVE $96.45 +2.31%
SUI $0.7612 -0.93%
XLM $0.1881 -3.47%
ZEC $514.49 -5.61%

cati

All
Article
Flash

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.

Gate gStocks has been fully upgraded, expanding the boundaries of tokenized securities applications with five major financial functions

Gate gStocks' tokenized securities service has undergone a comprehensive upgrade, officially launching five major financial functions: collateralized borrowing, idle asset management, unified accounts, leveraged trading, and stock dividends, further expanding the integrated application scenarios of stock assets from trading, yield management to liquidity management.Currently, gStocks supports over 58 global tokenized securities, covering various assets such as U.S. stocks, Korean stocks, unlisted equity, and ETFs, and employs a 1:1 native stock reserve mechanism to provide users with a transparent and trustworthy asset holding experience. At the same time, gStocks supports 24/7 trading with a minimum investment of 1 USDT, lowering the participation threshold. After this functional upgrade, users can release liquidity through collateralized borrowing without having to sell their held gStocks assets; idle stock assets can also participate in yield management through idle asset management. In addition, gStocks has deeply integrated into the Gate unified account system, supporting tokenized stock assets as trading collateral and providing features such as leveraged trading, long and short strategies, and stock dividends, further enhancing asset utilization efficiency.

macOS malware can bypass Telegram's two-factor authentication to steal cryptocurrency wallets and account permissions

According to FinanceFeeds, security researchers have discovered an information-stealing malware targeting macOS devices that is attacking cryptocurrency users. This malware can hijack Telegram Desktop sessions, steal passwords and wallet databases, further controlling user accounts and stealing digital assets. Currently affected wallets and applications include software wallets like Exodus, Atomic, Electrum, Wasabi, and Monero.The malware is capable of extracting sensitive information from macOS Keychain, Safari Cookies, Apple Notes, Telegram Desktop, and multiple cryptocurrency wallet-related databases, including login credentials, authenticated session files, wallet data, and browser extension information. Security analysis points out that the danger of this attack chain lies in its reliance not on a single wallet vulnerability, but on collecting various types of data from the device, linking device intrusion, account takeover, wallet cracking, and mnemonic phrase theft together. Among these, Telegram Desktop sessions have become a key target.Attackers can copy authenticated Telegram local session data and restore the login on another Mac device without needing to enter a phone number, verification code, or Telegram two-factor authentication password. This means that Telegram 2FA cannot provide complete protection in this attack scenario, as the attacker is not performing a new login but is exploiting an already trusted local session. For cryptocurrency users, the risks are further amplified. Since Telegram is widely used for exchange customer service, project communities, OTC trading, and wallet communication, once attackers gain access to user session permissions, they could impersonate the victim, read private chats, locate asset information, and even spread malicious links to contacts.
app_icon
ChainCatcher Building the Web3 world with innovations.