Loading market data...

Zilliqa Disables Legacy Transactions After Ledger Bug Exposes 6,772 Wallets, Drains 683M ZIL

Zilliqa Disables Legacy Transactions After Ledger Bug Exposes 6,772 Wallets, Drains 683M ZIL

What the bug actually did

" -> "

Lỗi thực sự đã làm gì

" or "Lỗi thực sự gây ra điều gì". I'll use "Lỗi thực sự đã làm gì". Then: "The problem was in the non-EVM signing path — code that Zilliqa originally wrote and Ledger maintained for years without either catching the flaw. The app was supposed to generate 40 random bytes for a signature, but it copied the wrong 32 bytes into the signing buffer. That left eight bytes of zero padding and tossed out eight bytes of entropy, forcing the high 64 bits of every affected nonce to zero." Vietnamese: "Vấn đề nằm ở đường dẫn ký không phải EVM — mã mà Zilliqa ban đầu viết và Ledger duy trì trong nhiều năm mà cả hai đều không phát hiện ra lỗ hổng. Ứng dụng được thiết kế để tạo 40 byte ngẫu nhiên cho chữ ký, nhưng nó đã sao chép sai 32 byte vào bộ đệm ký. Điều đó để lại tám byte đệm bằng không và loại bỏ tám byte entropy, buộc 64 bit cao của mỗi nonce bị ảnh hưởng phải về không." We need to explain "non-EVM signing path" - "đường dẫn ký không phải EVM". "code that Zilliqa originally wrote" - "mã mà Zilliqa ban đầu viết". "maintained" - "duy trì". "without either catching the flaw" - "mà cả hai đều không phát hiện ra lỗ hổng". "was supposed to generate" - "được thiết kế để tạo" or "được cho là tạo". "random bytes" - "byte ngẫu nhiên". "signature" - "chữ ký". "copied the wrong 32 bytes" - "sao chép sai 32 byte". "signing buffer" - "bộ đệm ký". "left eight bytes of zero padding" - "để lại tám byte đệm bằng không". "tossed out eight bytes of entropy" - "loại bỏ tám byte entropy". "forcing the high 64 bits of every affected nonce to zero" - "buộc 64 bit cao của mỗi nonce bị ảnh hưởng phải về không". Next: "That is a serious weakness. A nonce with 64 bits forced to zero means the signature math leaks information about the private key. Gather four or more biased signatures from the same account and an attacker can reconstruct the key from public blockchain data in seconds, on ordinary hardware." Vietnamese: "Đây là một điểm yếu nghiêm trọng. Một nonce có 64 bit bị buộc về không có nghĩa là phép toán chữ ký rò rỉ thông tin về khóa riêng tư. Thu thập bốn hoặc nhiều chữ ký lệch từ cùng một tài khoản,