And now, if the coordinator signs outputs with the same static blind key in all rounds, an attacker can accumulate those signatures and redeem them later to register additional outputs without contributing new inputs. It does not allow them to steal funds, but it breaks the round balances and causes it to fail, blocking all other participants (DoS).

And on top of that, they don't mitigate the vulnerability they've tried to remedy with this crap...

If they were at least humble, they would get help...

nostr:nevent1qvzqqqqqqypzpl8hpfzul2qha25p8wd63gm46ufax95lfgnl8h9v84y3zt0k05m7qqspg3vg7hachnkv3e3w9xc58v8hpanp2ku3y3n5huq2y47l7ynx7hgp4cknw

Reply to this note

Please Login to reply.

Discussion

No replies yet.