Practical Key-Extraction Attacks in Leading MPC Wallets

4Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Multi-Party Computation (MPC) has become a major tool for protecting hundreds of billions of dollars in cryptocurrency wallets. MPC protocols are currently powering the wallets of Coinbase, Binance, Zengo, BitGo, Fireblocks and many other fintech companies servicing thousands of financial institutions and hundreds of millions of end-user consumers. We present four novel key-extraction attacks on popular MPC signing protocols showing how a single corrupted party may extract the secret in full during the MPC signing process. Our attacks are highly practical (the practicality of the attack depends on the number of signature-generation ceremonies the attacker participates in before extracting the key). Namely, we show key-extraction attacks against different threshold-ECDSA protocols/implementations requiring 106, 256, 16, and one signature, respectively. In addition, we provide proof-of-concept code that implements our attacks.

Cite

CITATION STYLE

APA

Makriyannis, N., Yomtov, O., & Galansky, A. (2024). Practical Key-Extraction Attacks in Leading MPC Wallets. In CCS 2024 - Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (pp. 3053–3064). Association for Computing Machinery, Inc. https://doi.org/10.1145/3658644.3670359

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free