logo

Lattice-free half-half attack on Bitcoin and Ethereum

ID: 50a230cb-0f00-5f16-8958-483f8bebf8b7

STIX ID: report--50a230cb-0f00-5f16-8958-483f8bebf8b7

Feed Name: Kudelski Security

Threat Score
55/100

Date Published: 2023-07-11

Date Updated: 2026-07-22

...
...

This report analyzes a weakness in certain ECDSA nonce generation schemes (notably a “half-half” method) and demonstrates that the authors’ Polynonce algebraic attack can recover private keys from signatures produced with that flawed nonce construction; they ran the attack on a Bitcoin blockchain dump and recovered 110 private keys (no non-zero balances found), discuss relations to prior lattice attacks that can recover keys from biased nonces (including single-signature attacks), and publish tooling and results for further analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.