Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You can't spend at all without the private keys of the whales because the network nodes won't trust the chain.

Here is a simple library to recover the private key of ECDSA and DSA signatures sharing the same nonce k and therefore having identical signature parameter r

[1] https://github.com/tintinweb/ecdsa-private-key-recovery



That only gets you access to the private keys of specific accounts that had previously made transactions in a specific insecure way in old uncommon and no-longer-used clients. That's not at all a generic attack.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: