Reusing Nonce in P2PKH Addresses: Security Risks

19 replies 347 views
chain1337Hero Member
Posts: 58 · Reputation: 3203
#1Oct 17, 2023, 06:27 PM
Hey everyone, I stumbled upon some P2PKH address pairs that were created in a messed-up virtual environment. Turns out the same nonce r was reused between them. Here’s what I noticed: 1. TX 1 r = 5c16a3fbafc1ef0 Public Key = 956fb654bcb2e061 2. TX 2 (just 3 days later) r = 5c16a3fbafc1ef0 Public Key = 4b20eabe93918281 Both transactions sent money to the same address, which reused the nonce k with the same private key. Crazy, right?
4 Reply Quote Share
gang2015Member
Posts: 215 · Reputation: 62
#2Oct 17, 2023, 11:18 PM
Not sure what your endgame is, but using RFC 6979 would totally avoid this. Different keys with the same message hash will always result in different k values.
4 Reply Quote Share
m1kes4tFull Member
Posts: 43 · Reputation: 252
#3Oct 18, 2023, 02:00 AM
Just because you have two signatures for different private keys using the same nonce, doesn’t mean you can figure out the private keys. Even if they used the same nonce. But if you get two signatures with the same nonce for the same private key, that's a whole different story.
5 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#4Oct 18, 2023, 07:06 AM
A little more context: Example addresses: 1AxP2pkhFakeAddressExample1111 1A1P2pkhFakeAddressExample2222 1A2P2pkhFakeAddressExample3333... So, multiple addresses sent funds to 1Ax while Ax reused the same nonce k, making Ax compromised. Also, it shared k with others, putting them at risk too.
3 Reply Quote Share
m1kes4tFull Member
Posts: 43 · Reputation: 252
#5Oct 18, 2023, 11:14 AM
What’s your transaction setup? Reusing nonces like this is super risky. If Ax signed twice with the same nonce, the private key’s exposed. You can figure out the nonce and then get all private keys linked to it. Move your funds to a secure place ASAP.
1 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#6Oct 19, 2023, 11:56 AM
Sometimes, these issues show up in the same transaction. Look at these: Trx 1: Ax > A1 > A2 > Ax > A3 > A4 And so on. I’m digging into cases where nonces were reused across addresses in later transactions.
2 Reply Quote Share
m1kes4tFull Member
Posts: 43 · Reputation: 252
#7Oct 19, 2023, 02:32 PM
If you have the private key for Ax, then you can get the private keys for any other address that shared its nonce. Idea is to move the funds to a safe wallet before anything happens.
1 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#8Oct 20, 2023, 09:54 PM
I only have Ax’s private key. The other ones that shared the nonce are empty. But A4 and A5 interest me since their transactions were just three days apart. It’s like we have a system with more variables than equations.
3 Reply Quote Share
m1kes4tFull Member
Posts: 43 · Reputation: 252
#9Oct 20, 2023, 11:01 PM
The nonce used by those two signatures doesn’t link back to Ax, though. Are you considering A4 and A5 as derivatives of Ax? Focus on deriving from Ax instead of those two.
0 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#10Oct 21, 2023, 01:08 AM
I think A1 through A8 are children of Ax. They all sent to Ax on the same day and sometimes in the same transaction. Just a reminder, these addresses are quite old, created around 2015.
5 Reply Quote Share
mike2015Newbie
Posts: 1 · Reputation: 39
#11Oct 21, 2023, 01:46 AM
Let’s look back at an earlier example. Someone compiled a list of the most reused r values ever. Top ranked used thousands of times. We could analyze those.
2 Reply Quote Share
0xNodeMember
Posts: 257 · Reputation: 80
#12Oct 21, 2023, 04:24 AM
Been there, done that. I used some method to consolidate tiny outputs in the past. My transactions were small and got included quickly beat the bots. So, about that transaction you mentioned, thoughts?
2 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#13Oct 21, 2023, 06:06 AM
Yeah, totally different format, but you noticed the R and S values, right?
2 Reply Quote Share
0xNodeMember
Posts: 257 · Reputation: 80
#14Oct 21, 2023, 10:34 AM
Going back to that nonce reuse situation, have you seen cases where two keys reused the same nonce multiple times? Wondering if there's a way to recover private keys from this or any other method.
0 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#15Oct 21, 2023, 01:47 PM
Even with R, S, Z, P, you can create a lot of valid outputs, but without knowing how K was picked, it’s just math without substance.
2 Reply Quote Share
0xNodeMember
Posts: 257 · Reputation: 80
#16Oct 21, 2023, 03:57 PM
Those P2PKH addresses are compromised for sure. With around 4 BTC at stake, it’s a problem. I want to brute-force the nonce or come up with any clever way to recover it.
1 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#17Oct 21, 2023, 09:25 PM
Do you catch my drift? I can provide valid R, S, Zn, Pn sets for any R, S, but without knowing how 'K' was generated, it’s kinda useless.
2 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#18Oct 23, 2023, 08:04 AM
Have you seen any similar issues like this? Any efficient brute-force methods for situations like this?
0 Reply Quote Share
0xNodeMember
Posts: 257 · Reputation: 80
#19Oct 23, 2023, 09:02 AM
Sure, just message me. I got some insights.
3 Reply Quote Share
chain1337Hero Member
Posts: 58 · Reputation: 3203
#20Oct 23, 2023, 12:12 PM
So, looking back, one of the addresses has a bit over 2 BTC and there’s a pattern across 6 RSZ signatures. The second signature shares an r value with some empty addresses.
4 Reply Quote Share

Related topics