Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Subscribe
Money Visa
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
Secured #5: Public Vulnerability Disclosures Update
  • Forex

Secured no. 1 | Ethereum Foundation Blog

  • August 3, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0

Earlier this year, we launched a bug bounty program focused on finding issues in the beacon chain specification, and/or in client implementations (Lighthouse, Nimbus, Teku, Prysm etc…). The results (and vulnerability reports) have been enlightening as have the lessons learned while patching potential issues.

In this new series, we aim to explore and share some of the insight we've gained from security work to date and as we move forward.

This first post will analyze some of the submissions specifically targeting BLS primitives.

Disclaimer: All bugs mentioned in this post have been already fixed.

BLS is everywhere

A few years ago, Diego F. Aranha gave a talk at the 21st Workshop on Elliptic Curve Cryptography with the title: Pairings are not dead, just resting. How prophetic.

Here we are in 2021, and pairings are one of the primary actors behind many of the cryptographic primitives used in the blockchain space (and beyond): BLS aggregate signatures, ZK-SNARKS systems, etc.

Development and standardization work related to BLS signatures has been an ongoing project for EF researchers for a while now, driven in-part by Justin Drake and summarized in a recent post of his on reddit.

The latest and greatest

In the meantime, there have been plenty of updates. BLS12-381 is now universally recognized as the pairing curve to be used given our present knowledge.

Three different IRTF drafts are currently under development:

  1. Pairing-Friendly Curves
  2. BLS signatures
  3. Hashing to Elliptic Curves

Moreover, the beacon chain specification has matured and is already partially deployed. As mentioned above, BLS signatures are an important piece of the puzzle behind proof-of-stake (PoS) and the beacon chain.

Recent lessons learned

After collecting submissions targeting the BLS primitives used in the consensus-layer, we're able to split reported bugs into three areas:

  • IRTF draft oversights
  • Implementation mistakes
  • IRTF draft implementation violations

Let's zoom into each section.

IRTF draft oversights

One of the reporters, (Nguyen Thoi Minh Quan), found discrepancies in the IRTF draft, and published two white papers with findings:


While the specific inconsistencies are still subject for debate, he found some interesting implementation issues while conducting his research.

Implementation mistakes

Guido Vranken was able to uncover several “little” issues in BLST using differential fuzzing. See examples of those below:


He topped this off with discovery of a moderate vulnerability affecting the BLST's blst_fp_eucl_inverse function.

IRTF draft implementation violations

A third category of bug was related to IRTF draft implementation violations. The first one affected the Prysm client.

In order to describe this we need first to provide a bit of background. The BLS signatures IRTF draft includes 3 schemes:

  1. Basic scheme
  2. Message augmentation
  3. Proof of possession

The Prysm client doesn't make any distinction between the 3 in its API, which is unique among implementations (e.g. py_ecc). One peculiarity about the basic scheme is quoting verbatim: ‘This function first ensures that all messages are distinct' . This was not ensured in the AggregateVerify function. Prysm fixed this discrepancy by deprecating the usage of AggregateVerify (which is not used anywhere in the beacon chain specification).

A second issue impacted py_ecc. In this case, the serialization process described in the ZCash BLS12-381 specification that stores integers are always within the range of [0, p – 1]. The py_ecc implementation did this check for the G2 group of BLS12-381 only for the real part but did not perform the modulus operation for the imaginary part. The issue was fixed with the following pull request: Insufficient Validation on decompress_G2 Deserialization in py_ecc.

Wrapping up

Today, we took a look at the BLS related reports we have received as part of our bug bounty program, but this is definitely not the end of the story for security work or for adventures related to BLS.

We strongly encourage you to help ensure the consensus-layer continues to grow safer over time. With that, we look forward hearing from you and encourage you to DIG! If you think you've found a security vulnerability or any bug related to the beacon chain or related clients, submit a bug report! 💜🦄

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
Polestar Automotive Holding UK PLC (PSNY) Secures 0M Investment to Accelerate EV Expansion
  • Business

Polestar Automotive Holding UK PLC (PSNY) Secures $200M Investment to Accelerate EV Expansion

  • August 3, 2025
  • Roubens Andy King
Read More
Next Article
XRP Must Hold .65 Support Or Risk Major Breakdown – Analyst
  • Crypto

XRP Must Hold $2.65 Support Or Risk Major Breakdown – Analyst

  • August 3, 2025
  • Roubens Andy King
Read More
You May Also Like
Is Bukele the Next Chávez? Salvadoran Legislative Assembly Passes ‘Indefinite’ Re-Election Reform
Read More
  • Forex

Is Bukele the Next Chávez? Salvadoran Legislative Assembly Passes ‘Indefinite’ Re-Election Reform

  • Roubens Andy King
  • August 3, 2025
More Work, Less Reward? Bitcoin Mining Toughens As Price Sinks To 3K
Read More
  • Forex

More Work, Less Reward? Bitcoin Mining Toughens As Price Sinks To $113K

  • Roubens Andy King
  • August 3, 2025
5 Countries Where Crypto Is Tax-Free in 2025 (And Still Legal)
Read More
  • Forex

5 Countries Where Crypto Is Tax-Free in 2025 (And Still Legal)

  • Roubens Andy King
  • August 3, 2025
Investor Behavior Shifts After Months Of Decline
Read More
  • Forex

Investor Behavior Shifts After Months Of Decline

  • Roubens Andy King
  • August 3, 2025
Arthur Hayes Says Bitcoin, Ether Could Fall On Macro Headwinds
Read More
  • Forex

Arthur Hayes Says Bitcoin, Ether Could Fall On Macro Headwinds

  • Roubens Andy King
  • August 3, 2025
Over 1-M Ethereum Withdrawn From Exchanges In 2 Weeks: Supply Shock Incoming?
Read More
  • Forex

Over 1-M Ethereum Withdrawn From Exchanges In 2 Weeks: Supply Shock Incoming?

  • Roubens Andy King
  • August 3, 2025
Arthur Hayes Says Bitcoin, Ether Could Fall On Macro Headwinds
Read More
  • Forex

Arthur Hayes Says Bitcoin, Ether Could Fall On Macro Headwinds

  • Roubens Andy King
  • August 3, 2025
Vitalik Buterin & Tomasz K. Stańczak dropped big news at ETHKyiv 2025
Read More
  • Forex

Vitalik Buterin & Tomasz K. Stańczak dropped big news at ETHKyiv 2025

  • Roubens Andy King
  • August 2, 2025

Recent Posts

  • New Orleans woman’s dad blames his kids for being ‘broke’ — but Dave Ramsey accuses him of not being ‘a man of honor’
  • A Case for Broadening Retail Access to Private Markets
  • When Rupert Murdoch dies, it could plunge the Fox and News Corp empire into civil war
  • Top Wall Street analysts pick these 3 stocks for their growth potential
  • Walmart, CVS, Panera and more quietly close more stores
Featured Posts
  • New Orleans woman’s dad blames his kids for being ‘broke’ — but Dave Ramsey accuses him of not being ‘a man of honor’ 1
    New Orleans woman’s dad blames his kids for being ‘broke’ — but Dave Ramsey accuses him of not being ‘a man of honor’
    • August 3, 2025
  • A Case for Broadening Retail Access to Private Markets 2
    A Case for Broadening Retail Access to Private Markets
    • August 3, 2025
  • When Rupert Murdoch dies, it could plunge the Fox and News Corp empire into civil war 3
    When Rupert Murdoch dies, it could plunge the Fox and News Corp empire into civil war
    • August 3, 2025
  • Top Wall Street analysts pick these 3 stocks for their growth potential 4
    Top Wall Street analysts pick these 3 stocks for their growth potential
    • August 3, 2025
  • Walmart, CVS, Panera and more quietly close more stores 5
    Walmart, CVS, Panera and more quietly close more stores
    • August 3, 2025
Recent Posts
  • These Are the Photoshop AI Tools Worth Using: How I Use AI to Edit My Photos
    These Are the Photoshop AI Tools Worth Using: How I Use AI to Edit My Photos
    • August 3, 2025
  • Solana Brewing Cup-And-Handle Pattern Suggests Drop To 0 – Details
    Solana Brewing Cup-And-Handle Pattern Suggests Drop To $140 – Details
    • August 3, 2025
  • Is Bukele the Next Chávez? Salvadoran Legislative Assembly Passes ‘Indefinite’ Re-Election Reform
    Is Bukele the Next Chávez? Salvadoran Legislative Assembly Passes ‘Indefinite’ Re-Election Reform
    • August 3, 2025
Categories
  • Business (1,342)
  • Crypto (736)
  • Economy (105)
  • Finance Expert (1,185)
  • Forex (736)
  • Invest News (1,626)
  • Investing (909)
  • Tech (1,327)
  • Trading (1,311)
  • Uncategorized (1)
  • Videos (777)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.