Home Crypto Currency New Bitcoin upgrade catches hidden key leaks hiding the exact fix

New Bitcoin upgrade catches hidden key leaks hiding the exact fix

by Deidre Salcido
0 comments
Exec 01893f5d 1d51 4e97 bff2 96f6e73bb8aa.png

Bitcoin improvement proposal BIP461 could make a hidden route for leaking wallet secrets easier to detect. The draft defines a common signing procedure for ECDSA, an existing Bitcoin signature scheme.

Independent compliant signers should produce identical signatures for the same secret key and message hash, creating a benchmark for detecting departures that could conceal key leakage.

Authored by Liam Gilligan, the proposal was merged into the BIPs repository on Sept. 16 and remains marked Draft. Its signatures work under existing Bitcoin consensus rules, so implementing this signing procedure requires no consensus change.

Comparing signatures for deviations

ECDSA allows a signer choices while creating a valid signature, including the nonce, a temporary value used in signing. Malicious firmware can exploit that freedom to hide key material in signatures that still pass verification, and BIP461 fixes those choices through a specified deterministic procedure.

Bitcoin’s acceptance of a signature cannot establish that its creation kept the key safe. A common specification supplies an expected output against which the signer’s behavior can be checked.

The comparison requires identical inputs and the exact same standard, including access to the secret key on another independent signer. That extra exposure is a practical cost of reproducing the signature. Different results for the same key and message hash show that at least one signer is not following BIP461.

An honest implementation using another valid ECDSA procedure can also disagree. A mismatch warrants investigation into compliance, but its cause remains unresolved. The comparison alone cannot identify a malicious device or demonstrate theft.

Related Reading

No dice? Your Bitcoin hardware wallet is probably not as secure as you thought it was

The prescribed algorithm also keeps signatures to at most 70 bytes in the standard DER encoding, excluding Bitcoin’s one-byte sighash flag.