Impact
UltrafastSecp256k1’s ECDSA adaptor verification omitted a proof of knowledge that binds the ‘r’ component of a pre‑signature to the adaptor point ‘T’. The missing DLEQ binding means adversaries can supply a forged adaptor pre‑signature whose ‘r’ value is not tied to ‘T’. If accepted, the verifier may accept a signature that can be used outside the intended cryptographic protocol, effectively enabling signature forgery or malicious manipulation of the cryptographic state. This weakness directly undermines the integrity guarantees of any system that relies on these adaptor signatures for authentication or transaction authorization.
Affected Systems
The vulnerability affects the shrec UltrafastSecp256k1 library in all releases before version 4.2.0. Applications that link to those versions and perform adaptor signature verification are at risk. Versions 4.2.0 and later contain the fix and are not affected.
Risk and Exploitability
The CVSS score of 5.9 classifies the flaw as moderate; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation reports. The attack likely requires the ability to influence or supply a pre‑signature to the verifier—typically a local or compromised application context. Because the flaw is tied to cryptographic logic, an active adversary who can inject or replace an adaptor pre‑signature could cause the verifier to accept forged data, leading to potential denial of service, authentication bypass, or transaction manipulation depending on the application.
OpenCVE Enrichment