Poster: Signer Discretion is Advised: On the Insecurity of Vitalik's Threshold Hash-based Signatures

No ratings

Presented at ACM CCS 2023 by

We show that the Lamport threshold signature scheme proposed by Vitalik Buterin is not existentially unforgeable under chosen message attacks (EU-CMA). In this work, we formalize the proposed threshold hash-based signature scheme, and show an attack that results in a 60-bit security reduction. Our attack completes in seconds in a setting with a single malicious adversary (the leader of a consensus round), thus contradicting the claim that even with 96 malicious colluding participants (out of a total of 256), an adversary can only make a signature for approximately 1 in 280 possible values. In summary, the original estimated security analysis of the proposed threshold signature scheme claimed security against an adversary in control of approximately a year of continuous work from the entire bitcoin network. Our attack, however, runs in seconds using a commodity laptop.