So where does that leave us? The best candidate explanation so far is from Ava Labs'
@_patrickogrady: A potential nonce reuse that ends up revealing the private key.
I wonder if there’s a nonce reuse bug in some ed25519 signature library solana projects are using. I think this would allow any attacker looking at solana to derive the private key regardless of where it was generated. Here’s an article that covers this: blog.trailofbits.com/2020/06/11/ecd…

