RE: LeoThread 2026-05-18 20-40

You are viewing a single comment's thread:

The exact leakage path hasn't been proven yet, but it appears to be a GG20 bug analogous to a Paillier-modulus attack: a malicious participant can publish a malformed Paillier modulus during keygen, then leverage later signing/MtA rounds to extract honest parties’ ECDSA shares.



0
0
0.000
2 comments
avatar

Recent GG20 patches likely mitigate this, but the recommendation is for Thorchain to migrate to DKLS with the library maintained by an active maintainer

0
0
0.000
avatar

Reproducing the suspected GG20 leakage mechanics against the tss-lib version used shows it accepts malformed Paillier material, exposes a type 5 / type 7 oracle shape, and the go-tss wrapper omits several important checks

0
0
0.000