Junglewise Threat Intelligence

Elliptic ECDSA private key extraction via malformed input

Severity: medium · CVSS 4 · Published 2025-02-12

Technologies: elliptic (npm). Vendors: npm.

Executive brief

Elliptic is a widely-used cryptographic library that implements ECDSA digital signing. A flaw in how it processes malformed input (such as strings) during signature generation causes the same cryptographic nonce to be reused for different messages. This nonce reuse allows an attacker to extract the complete private key after seeing just two signatures, potentially compromising all security operations that depend on that key.

Technical details

The vulnerability is a cryptographic key reuse bug in the ECDSA signing implementation. When processing the message input before signing, the library converts it to a BigNumber (BN) instance; however, the nonce derivation converts a BN to a byte array without accounting for potential representation differences. Different BN values can serialize to identical byte arrays, causing identical nonces to be generated for different messages. An attacker can construct a malformed message (e.g., a hex string or number) that, when signed, produces a nonce collision with a previously-obtained signature. With two signatures sharing the same nonce but different messages, the attacker can solve simultaneous equations to extract the private key. Attack requires the ability to influence a message being signed, but exploitation succeeds after only one such malicious message is processed. The vulnerability affects all versions up to and including 6.6.0; version 6.6.1 contains the fix.

Affected products

  • indutny elliptic <=6.6.0

Timeline

  • 2025-02-12: disclosed
  • 2025-02-12: patched: version 6.6.1

References

Related threats