Project Eleven found a key-recovery flaw in the reference implementation of the first fully ML-DSA-compatible threshold signature scheme, which could expose a signer's secret share and aggregate signing secret if reusing signing state is not properly managed.
Public source
Publisher name
Public post
We found a key-recovery flaw in the reference implementation of the first fully ML-DSA-compatible threshold signature scheme. Reusing signing state could expose a signer…
Company
Project Eleven
Securing digital assets for the post-quantum era
- Industry
- Technology, Information and Internet
- Company size
- 11–50 employees
About Project Eleven
Securing digital assets for the post-quantum era Follow us on X: https://x.com/projecteleven
See moreDiscover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Cloudflare
Cloudflare's team broke down why NIST standardized ML-DSA for post-quantum signatures introduces a massive 20x payload size increase compared to classical crypto.
Research & Knowledge
PQShield
PQShield published a white paper examining the pitfalls in benchmarking ML-DSA and how traditional methods fail to model its behavior.
Research & Knowledge
Hacken, Blockchain Security & Compliance
Hacken, Blockchain Security & Compliance published current analysis of the Elements source and disputed blocks pointing to the range-proof verification cache, which omitted the asset commitment and script context.
Research & Knowledge
CredShields
CredShields wrote up how a Bitcoin sidechain approved a $320 million withdrawal that should never have been possible, detailing the bug in Elements and the protocol honoring it.
Research & Knowledge
Encryption Consulting LLC