时间点
第一轮 exchange migration 计划在 block 34,844,968 激活,预计约 9 月 2 日 12:58 UTC。本次日报生成时该时间点尚未到,因此不能写成已经完成。
Root Cause
旧版 Ledger app 在 Schnorr nonce copy 时错误保留 8 bytes zero padding,同时丢掉 8 bytes entropy,导致 top 64 bits 固定为 0,只剩 192 bits 有效随机性,从而允许从 public signatures 恢复 private key。
Proven Scope
官方数据:683,130,969.66 ZIL proven theft、6,772 known exposed accounts、51 drained accounts、73.9% attributable legacy addresses safe by construction。
Fork 做什么
第一批 fork 在 protocol-state 层面把 legitimate exchange balances 从 legacy Schnorr addresses 迁到 verified Zilliqa EVM addresses。首批包括 KuCoin、MEXC、OKCoin、Binance US、Bitvavo、DigitalX/Korbit、Indodax、Bitrue、WhiteBIT、CoinSpot、CoinSwitch。
Stolen Balance 与 Self-custody
Identified attacker balances 不会被恢复。第一批主要服务 CEX,legacy self-custody holder 需要等待 broader migration/recovery guidance。
Evidence Status
Confirmed: Root cause、proven theft、exposure count、target block、first batch、stolen balance exclusion。
Developing: final theft ceiling、asset recovery、later batches、self-custody migration。
Risk Assessment
Critical。 Recovery fork 不代表原 private-key exposure 风险轻微。
What to Watch Next
Fork activation、CEX migration、deposit/withdrawal reopen、later batches、self-custody tool、asset tracing、phishing。
FAQ
Hard Fork 已完成吗?
本次报告生成时还没有。
被盗多少?
683,130,969.66 ZIL proven theft。
Attacker balance 会迁移吗?
不会。