Exploring ECDSA Signature Vulnerabilities

1 reply 438 views
dan2015Hero Member
Posts: 41 · Reputation: 3344
#1Apr 27, 2022, 04:05 PM
Just built a suite for ECDSA secp256k1 to see how signatures hold up against various attacks. It's aimed at helping devs spot weaknesses in their code. Honestly, I wish I could include every known issue but time's been tight. If anyone's interested in improving this tool, hit me up with pull requests. Also, if you find any bugs, let me know!
4 Reply Quote Share
benlordMember
Posts: 7 · Reputation: 197
#2Apr 27, 2022, 07:42 PM
Here’s an updated version of your code, now it runs smoothly. Just execute it and wait a bit to see the k Nonce pop up. To confirm the script works, I included three signatures with a k nonce of only 20 bits: 1. r = 0x6f007fe0bc2a1a0f6d944b8d4a2353e48833e1f6be178f87f293068b25d6d96e s = 0xea5459e9fb80101fbc261b90c59bf20dc497f5f71c90356c9530d035d32bd023 z = 0x840131231b57268049ccbd6b2c84408251b935cb951c069ecb86cf8d4755bf34 k = 0xb37b1 2. r = 0xdc52f02499d8859b4be4a517898e23f42bd409d5d1ef0f9e49edf775c49aab93 s = 0x120e526332349b7ebe20565240feeb224ed1f0886990d70513a83cb6d941c648 z = 0xa4075d10756be846ad1 Try it out!
3 Reply Quote Share

Related topics