Generating Signatures Using Only Public Key

2 replies 457 views
dan2015Hero Member
Posts: 41 · Reputation: 3344
#1Oct 10, 2025, 05:30 AM
So, here's the deal. I figured out that you can usually create valid signatures with the private key for ecdsa secp256k1. There are libraries out there for this. But I noticed something interesting... if you keep the same values for u1, u2 and just use the public key, you can actually generate signatures with the same r, s, z values. So yeah, random u1 and u2 gives you multiple valid signatures just with the public key. Pretty wild, huh? You can check out my code here if you wanna test it out.
6 Reply Quote Share
wizard_2016Full Member
Posts: 127 · Reputation: 575
#2Oct 10, 2025, 05:48 AM
Not really my area of expertise, but if z isn't tied to the message, then that same signature could work for any message. Just saying... If someone wanted to fake a signature pretending to be Satoshi, how could they do it without getting caught?
1 Reply Quote Share
dan2015Hero Member
Posts: 41 · Reputation: 3344
#3Oct 10, 2025, 06:41 AM
I skimmed that. Got some ideas brewing now. The formula mentioned is basically what I've been talking about, same concept. Two random scalar values for the r sig, but the stuff mentioned there is sparking some theories in my head. Appreciate it!
6 Reply Quote Share

Related topics