Reusing Nonces in ECDSA Signatures: A Critical Look

4 replies 137 views
lynx_coinFull Member
Posts: 2 · Reputation: 603
#1Jul 8, 2024, 05:48 AM
Check this out, a scenario with ECDSA signatures on secp256k1 where nonces aren’t following RFC6979. We have 7 private keys and 3 nonces reused across them. 9 valid signatures available, but no known keys or nonces.
2 Reply Quote Share
Posts: 110 · Reputation: 19
#2Jul 8, 2024, 12:11 PM
Sounds complicated. You can’t solve it, right? Just too many unknowns compared to equations. Maybe those reused nonces hint at something more significant going on... or just a total mess.
5 Reply Quote Share
QuantumOmegaSenior Member
Posts: 8 · Reputation: 832
#3Jul 10, 2024, 03:33 AM
Nah, it's solvable if you have the same r value repeated in two transactions. Just grab r, s1, s2, z1, z2. Simple math in Python lets you isolate k and find the private key. Just look at this formula: k = (z1 z2) / (s1 s2) mod n d = ((s1 * k z1) / r) mod n And yeah, there are tools to check if your address has reused r values.
4 Reply Quote Share
bear_2020Member
Posts: 6 · Reputation: 67
#4Jul 11, 2024, 07:41 PM
@mr.jeanfrancois, did you miss the point? It’s not just about finding one of the nonces or private keys. You have to know something about those k values or d1-d7 to even start.
0 Reply Quote Share
lynx_coinFull Member
Posts: 2 · Reputation: 603
#5Jul 12, 2024, 01:42 AM
I see your perspective, but it’s a different situation here. We know d1 is significant and have some clues about k values. The entropy levels suggest leakage that can be exploited. There’s a chance to dig into some dormant BTC in compromised wallets.
1 Reply Quote Share

Related topics