
Moksh.hl
23.4K posts

Moksh.hl
@dmoksh1
https://t.co/GvaKZhme2U $hype $btc $hypurr



Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated with a predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key using only publicly available on-chain data. Protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalised. Users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action. Impact: The vulnerability affects private keys used to sign native Zilliqa transactions with a Ledger device. Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should be considered compromised. Its private key can be reconstructed from signatures already recorded on-chain, regardless of any subsequent software update. The issue is confined to the Ledger app’s native signing path. EVM transactions are unaffected. Zilliqa software development kits, including zilliqa-js, gozilliqa-sdk and pyzil, generate nonces correctly and are not affected. Root cause: Zilliqa native transactions are authenticated using EC-Schnorr signatures over secp256k1. Each signature requires a fresh, uniformly random 256-bit ephemeral nonce, (k). The secrecy and full-width randomness of (k) are essential, as any systematic bias can allow the private key to be recovered. The signing routine generated 40 bytes of randomness and reduced them modulo the curve order, correctly producing a uniform 256-bit value. However, when copying this value into the nonce buffer, the code copied the wrong 32 bytes of the 40-byte output. This retained the eight zero-padding bytes introduced by the reduction and discarded eight bytes of entropy. As a result, the most significant 64 bits of every generated nonce were fixed at zero, meaning (k < 2^{192}). A nonce with 64 known bits leaks information about the private key with each signature. With five or more affected signatures, the private key can be recovered in seconds using commodity hardware by solving the resulting Hidden Number Problem through lattice reduction - a well-documented technique for attacking biased-nonce signatures. Because the affected transactions are permanently recorded on-chain, this exposure cannot be reversed by updating the signing application. The affected keys must be retired. Timeline 2019-2026: The defect was present in every released version of the Zilliqa Ledger app across all supported devices. 19 July 2026: On-chain activity consistent with active exploitation was observed. 21 July 2026: The root cause was isolated to the app’s nonce-handling code and confirmed by reproducing the issue against on-chain signatures. Ongoing: A corrected version of the app is being prepared in coordination with Ledger. Release details will be announced separately. Remediation: As soon as the issue was identified, native (non-EVM) transactions were suspended as a protective measure. This has halted further draining of affected accounts while a solution is prepared. Affected accounts cannot be secured through an ordinary transfer. Because their private keys can be derived from data already recorded on-chain, an attacker with access to the same key could attempt to front-run a legitimate transfer as soon as transactions resume. Advising users simply to move their funds would therefore be ineffective and potentially unsafe. A corrected build of the Ledger app has been prepared, restoring full-width nonce generation and preventing further weakened signatures from being produced. However, this does not protect keys that have already been used to sign affected transactions. Those keys must ultimately be retired. A coordinated remediation plan to secure affected balances is being finalised and will be published separately. Until then, users who have signed native Zilliqa transactions with a Ledger device should take no independent action and should rely solely on official Zilliqa channels for instructions. Users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected. Acknowledgments: @kucoincom played a key role in pinpointing the root cause in the Zilliqa Ledger app nonce generation, recovered affected private keys from publicly available on-chain signatures, and confirmed ongoing exploitation. KuCoin’s timely reporting and responsible collaboration enabled rapid protective measures, helping safeguard users, ecosystem participants, and the broader Zilliqa ecosystem while the remediation plan was being developed. We sincerely appreciate the KuCoin team’s professionalism, technical expertise, and cooperation throughout this process.






We are entering a new era for DeFi. For the first time ever, @HyperliquidX generated more volume from RWAs than crypto in a single week. RWAs accounted for 54% of total trading volume. An even more interesting trend: since June, single stocks have overtaken indices and commodities on HIP-3. Today, 61% of all RWA trading volume is in individual equities. I’m no longer convinced RWA trading will naturally aggregate on the same venue as crypto. There will likely be category leaders within RWA, and owning BTC/ETH/SOL flow may become far less important than many people assume. To put this into perspective: Total DEX perpetual volume last week: $79B Hyperliquid: $50B Of that, $26B was HIP-3 RWA trading In other words, Hyperliquid’s RWA market alone was larger than the combined crypto perpetual volume of every other DEX. If you’re still only focused on crypto token trading, I think you’re focusing on the wrong market. data from @Blockworks






Included in Snapshot: @AbstractChain @Polymarket @PlayKintara @Pumpfun @Ronin_Network @apecoin @fantasy_top_ @HyperliquidX @onchainheroes @pudgypenguins @Azuki @moonbirds @rektguy @PirateNation @AxieInfinity @AxiomExchange @pumpcade @goblintown @GLHFers @Mocaverse_xyz and more






Seen this countless times. A client comes to me after years of believing the “fasted” training myth. We start placing a good amount of carbs pre training. Oatmeal, fruit (whatever digests well for them) They might be skeptical for a week or so. But once the wheels are spinning…they feel strong as fuck in the gym while dropping body fat. Carbs are rocket fuel. Better training performance = better physique. Hands down.



Multicoin Capital appears to be taking profits on 606,091 $HYPE ($36.5M) bought around $30 5 months ago. 6 hours ago, Multicoin Capital deposited 395,570 $HYPE($23.78M) into #CoinbasePrime and also requested to unstake 211,486 $HYPE($12.94M). Multicoin Capital's profit on $HYPE is now ~$18.5M. arkm.com/explorer/addre… #txs" target="_blank" rel="nofollow noopener">hypurrscan.io/address/0xaB31…


















