@theycallmejp's thread

theycallmejp
54
@theycallmejp
·

The exact leakage path hasn't been proven yet, but it appears to be a GG20 bug analogous to a Paillier-modulus attack: a malicious participant can publish a malformed Paillier modulus during keygen, then leverage later signing/MtA rounds to extract honest parties’ ECDSA shares.

No replies made yet. Would you like to be the one to do so?