Understanding Backdoor ECDSA: What's Going On?

8 replies 203 views
greg_moonMember
Posts: 16 · Reputation: 167
#1Sep 8, 2024, 09:36 PM
Hey everyone. I stumbled upon some code on github about a backdoor in ECDSA. I checked out the rsz values but I'm totally lost. Anyone know what the leaked values are and how they work?
4 Reply Quote Share
wizard_2016Full Member
Posts: 127 · Reputation: 575
#2Sep 9, 2024, 12:20 AM
Basically, the attacker manipulates the nonce selection so some secret can be extracted from each signature. The leaked secret could be anything, but in the example, it’s just a random value. The way it works is they compute k by mixing a small part of the secret with a value only they know. It's like exposing k when it shouldn't be.
0 Reply Quote Share
Posts: 23 · Reputation: 204
#3Sep 9, 2024, 01:30 AM
I got something similar a python script that simulates this. It generates random signatures with a 128-bit leak, then assumes they’re real transactions and uses LLL reduction to uncover the PrivateKey.
5 Reply Quote Share
greg_moonMember
Posts: 16 · Reputation: 167
#4Sep 10, 2024, 09:36 PM
Can I run your script with actual values? I’m not sure how to do that. Do you have to use trial and error to find b or is it just an integer?
2 Reply Quote Share
wizard_2016Full Member
Posts: 127 · Reputation: 575
#5Sep 12, 2024, 10:56 AM
Dude, b is chosen by the attacker. Your questions suggest you might need a better grip on cryptography before diving too deep into this.
5 Reply Quote Share
stacksatsHero Member
Posts: 404 · Reputation: 2023
#6Sep 12, 2024, 01:03 PM
Wait a minute... Can this code work without signing, or sending coins, or messages to the attacker? If it can, we could fake a public key using bits from the victim’s keys, right? How does that even work?
2 Reply Quote Share
stacksatsHero Member
Posts: 404 · Reputation: 2023
#7Sep 12, 2024, 04:35 PM
The author removed the repo.
5 Reply Quote Share
greg_moonMember
Posts: 16 · Reputation: 167
#8Sep 13, 2024, 08:32 PM
I asked something and it got deleted. Not sure why. Spent hours online trying to figure out how to use those leaked parts.
4 Reply Quote Share
stacksatsHero Member
Posts: 404 · Reputation: 2023
#9Sep 13, 2024, 10:43 PM
I’m using the leaked parts for matrix GF[2], but Bitcoin uses GF[7]. It’s a weird situation. I still don’t get what scrypt finds in the end. Got a clue? OpenAI mentioned different r and s from various privkey-message pairs... Are you following this?
3 Reply Quote Share

Related topics