banteg - Malformed Paillier Keys in THORChain’s TSS Stack

Malformed Paillier keys in THORChain's TSS stack
by mishaderidder.eth13093 🥝 • 5mo • banteg.xyz
AI summary of the linked article

A newly churned THORChain validator reconstructed the full ECDSA private key of one Asgard vault by exploiting flaws in THORChain's tss-lib v0.1.6 fork, then drained approximately USD 10.7M on 15 May 2026. The three flaws were a malformed 2048-bit Paillier modulus admitted during keygen, a degenerate range proof that accepted Z = 1, and a Bob proof with unbalanced ranges that leaked the Paillier mask. The attacker caused 864 signing failures over about two and a half days to obtain fresh MtA responses, then signed transactions directly without TSS. THORSec's later disclosure showed that the earlier abort-oracle and go-tss wrapper hypotheses were unnecessary.

avatar
fyi
On 15 May 2026, THORChain paused after a reported Asgard vault drain later traced to more than USD 11M across at least nine chains.
Characters remaining: 10,000

comment guidelines