June 6, 2023, 9:43 a.m. |

IACR News www.iacr.org

ePrint Report: The curious case of the half-half Bitcoin ECDSA nonces

Dylan Rowe, Joachim Breitner, Nadia Heninger


We report on a new class of ECDSA signature vulnerability observed in the wild on the Bitcoin blockchain that results from a signature nonce generated by concatenating half of the bits of the message hash together with half of the bits of the secret signing key. We give a lattice-based attack for efficiently recovering the secret key from a single signature of this …

bitcoin bits blockchain case class ecdsa eprint report generated message nonce report results signature vulnerability

Financial Crimes Compliance - Senior - Consulting - Location Open

@ EY | New York City, US, 10001-8604

Software Engineer - Cloud Security

@ Neo4j | Malmö

Security Consultant

@ LRQA | Singapore, Singapore, SG, 119963

Identity Governance Consultant

@ Allianz | Sydney, NSW, AU, 2000

Educator, Cybersecurity

@ Brain Station | Toronto

Principal Security Engineer

@ Hippocratic AI | Palo Alto