DEF CON 2019 CTF: Invalid Curve Attack Used to Extract CryptoNote Tracking Key
At DEF CON 2019, a Capture The Flag challenge called CaptureTheCoin tasked participants with exploiting a flaw in a CryptoNote-based digital currency client. The vulnerability involved an invalid curve attack on the brainpoolP160r1 elliptic curve, where malformed transaction points were sent to force the server into computations on a weaker, low-order curve. By analyzing error logs that leaked the server's computed secrets, participants could determine the private tracking key modulo several small group orders. Applying the Chinese Remainder Theorem to these residues allowed the full private tracking key to be reconstructed. The challenge demonstrated how improper elliptic-curve point validation in cryptographic implementations can lead to complete key compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in