hyperweb-io / hyperweb-io/interchainjs

private key exposure bug in elliptic

Open
#190 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
12
Forks
11
PR merge metrics
No merged PRs in 30d

Description

https://github.com/hyperweb-io/interchainjs/blob/8f4d8db571a278d178d9287f461d51e4718d042e/packages/crypto/src/secp256k1.ts#L3

This library uses `elliptic` for signing, which generates faulty signatures. That faulty signature combined with a correct signature can expose the private key. https://github.com/indutny/elliptic/issues/321#issuecomment-2658908675

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.