RE: LeoThread 2026-05-18 20-40
You are viewing a single comment's thread:
The exact leakage path hasn't been proven yet, but it appears to be a GG20 bug analogous to a Paillier-modulus attack: a malicious participant can publish a malformed Paillier modulus during keygen, then leverage later signing/MtA rounds to extract honest parties’ ECDSA shares.
0
0
0.000
Recent GG20 patches likely mitigate this, but the recommendation is for Thorchain to migrate to DKLS with the library maintained by an active maintainer