HistoryEditJSON (OSV)

RUSTSEC-2025-0130

Missing check in ZK proof in CGGMP21 Threshold Signing Protocol

Reported
Issued
Package
cggmp24 (crates.io)
Type
Vulnerability
Categories
Keywords
#zk-proof
Aliases
References
Patched
  • >=0.7.0-alpha.2

Description

Vulnerability concerns a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key.

Patches

References

Read our blog post to learn more.

Advisory available under CC0-1.0 license.