banteg - Malformed Paillier Keys in THORChain’s TSS Stack
Malformed Paillier keys in THORChain's TSS stack by mishaderidder.eth13093 🥝 • 5mo • | |
AI summary of the linked articleA newly churned THORChain validator reconstructed the full ECDSA private key of one Asgard vault by exploiting flaws in THORChain's tss-lib v0.1.6 fork, then drained approximately USD 10.7M on 15 May 2026. The three flaws were a malformed 2048-bit Paillier modulus admitted during keygen, a degenerate range proof that accepted Z = 1, and a Bob proof with unbalanced ranges that leaked the Paillier mask. The attacker caused 864 signing failures over about two and a half days to obtain fresh MtA responses, then signed transactions directly without TSS. THORSec's later disclosure showed that the earlier abort-oracle and go-tss wrapper hypotheses were unnecessary. | |
fyi On 15 May 2026, THORChain paused after a reported Asgard vault drain later traced to more than USD 11M across at least nine chains. | |
Characters remaining: 10,000 comment guidelines | |
More from banteg.xyz on Kiwi News | |
