Attacks on MPC and Threshold Signature Wallets

Added:

Trust Distribution
TSS Mechanisms
Core Cryptography
Attack Setup
Forget & Forgive
Ladder Rinse Repeat
Golden Shoe
Mitigation Advice

Trust Distribution

2:03
Playing Section
  • 1

    Explores enterprise wallet security and regulations like Swiss 4i control requiring multi-party approvals.

  • 2

    Introduces MPC and TSS as cryptographic methods to distribute trust without hardware or procedures.

  • 3

    Highlights the goal of avoiding single points of failure in financial institutions.

Fundamentals of Multi-Party Computation (MPC), including how private inputs are processed collaboratively without revealing individual secrets.
The mechanics of Threshold Cryptography and Threshold Signature Schemes (TSS) like Shamir's Secret Sharing and threshold ECDSA/EdDSA.
Basic asymmetric cryptography and key management principles in cryptocurrency wallets, particularly how public/private key pairs secure digital assets.
Common cryptographic attack vectors, such as side-channel attacks, replay attacks, and mathematical exploits in elliptic curve cryptography.
Implementation of defense-in-depth security measures and patch management for MPC-based wallet architectures.
Advanced cryptographic protocols designed to mitigate classic TSS vulnerabilities, such as FROST (Flexible Round-Optimized Schnorr Threshold) or newer CGGMP protocols.
Methods for formal verification and security auditing of threshold signature implementations and smart contracts.
Analyzing real-world case studies of MPC wallet exploits and the resulting regulatory and compliance standards for custodial cryptocurrency providers.
4.4K views112likes40:06@BlackHatOfficialYTOriginal Release: 2021-02-26

Multi-party computation (MPC) and threshold signature schemes (TSS), which are cryptographic techniques designed to distribute trust and protect cryptocurrency wallets by splitting private keys across multiple parties, can contain critical implementation vulnerabilities that allow attackers to extract private keys or permanently lock funds, as demonstrated by three distinct attacks: 'Forget and Forgive' (key rotation failure), 'Ladder Rinse Repeat' (key extraction through repeated queries), and 'Golden Shoe' (message manipulation to extract secrets), highlighting that theoretical cryptographic security does not automatically translate to practical implementation safety.