Exploring GCD Bias in Signature Generation

2 replies 103 views
0xC0br4Member
Posts: 1 · Reputation: 178
#1May 9, 2020, 09:49 AM
So, I stumbled on this sketchy crypto wallet about two months ago. It’s linked to some serious pigbutchering scams with a ton of transactions. It got me thinking there’s gotta be a flaw in the wallet that could help out the victims, right? I started digging in and noticed that some of the earliest signatures show a GCD bias of around 39% from when they were using a weak PRNG before that RFC 6797 thing was rolled out. There’s a window of like 3000 signatures that look off.
6 Reply Quote Share
0xDefiFull Member
Posts: 133 · Reputation: 317
#2May 9, 2020, 12:56 PM
You’re onto something with the weak PRNG theory, but a 30-40% bias is usually not enough to break through. If the bias gets weaker in later transactions, that means they probably fixed their implementation, which could explain why your lattice efforts didn’t pan out. Helping the victims is noble, but I wouldn’t bet on that wallet still having weak spots. Most recoveries happen through nonces that are reused or leaked, not just from bias. If you got a small anonymized batch of those signatures, it might help.
0 Reply Quote Share
j0hn.ga5Newbie
Posts: 98 · Reputation: 19
#3May 9, 2020, 07:11 PM
You really should narrow it down instead of looking at every transaction. Focus on that early batch where you know the RNG was bad and consistent. Maybe look at a few hundred signatures, not thousands. Anything after the fix doesn't help your case at all. Plus, if this whole pig-butchering thing is raking in millions, you can’t expect there’s just one hot wallet key floating around for years. There’s usually multiple keys and systems in play, so don’t get too fixated.
0 Reply Quote Share

Related topics