Skip to content

fix: correct sign of Paillier-decrypted s in ECDSA-2P signing resulting in a security bug - #124

Merged
hsiuhsiu merged 1 commit into
masterfrom
ecdsa-2p-s-fix
Jul 21, 2026
Merged

fix: correct sign of Paillier-decrypted s in ECDSA-2P signing resulting in a security bug#124
hsiuhsiu merged 1 commit into
masterfrom
ecdsa-2p-s-fix

Conversation

@hsiuhsiu

Copy link
Copy Markdown
Contributor

This fixes the security bug in the 2-party ECDSA protocol.

This fixes the security bug in the 2-party ECDSA protocol.
@cb-heimdall

cb-heimdall commented Jul 21, 2026

Copy link
Copy Markdown

✅ Heimdall Review Status

Requirement Status More Info
Reviews 2/2
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 2
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 1
Global minimum 0
Max 2
2
1 if commit is unverified 0
Sum 2
CODEOWNERS ✅ None for this change

@hsiuhsiu hsiuhsiu changed the title fix: correct sign of Paillier-decrypted s in ECDSA-2P signing fix: correct sign of Paillier-decrypted s in ECDSA-2P signing resulting in a security bug Jul 21, 2026
@hsiuhsiu
hsiuhsiu marked this pull request as ready for review July 21, 2026 15:41
@hsiuhsiu
hsiuhsiu requested a review from Arash-Afshar July 21, 2026 15:42

@valery-osheter-cb valery-osheter-cb left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@hsiuhsiu
hsiuhsiu merged commit 23b1ac6 into master Jul 21, 2026
9 checks passed
@hsiuhsiu
hsiuhsiu deleted the ecdsa-2p-s-fix branch July 21, 2026 18:50
@aussinfosec

Copy link
Copy Markdown

Hello @Arash-Afshar @valery-osheter-cb

I was wondering if you could please respond to the report #3856040 where I had identified this. It's still pending program review. Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

5 participants