RUSTSEC-2025-0130
Missing check in ZK proof in CGGMP21 Threshold Signing Protocol
Details
Vulnerability concerns a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full private key.
### Patches * `cggmp21 v0.6.3` is a patch release that contains a fix that introduces this specific missing check. * However, we recommend upgrading to `cggmp24 v0.7.0-alpha.2` in which we've introduced many other security checks as a precaution. Follow the [migration guidelines](https://github.com/LFDT-Lockness/cggmp21/blob/v0.7.0-alpha.2/CGGMP21_MIGRATION.md) to upgrade.
### References Read our [blog post](https://www.dfns.co/article/cggmp21-vulnerabilities-patched-and-explained) to learn more.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.7.0-alpha.2Upgrade cggmp24 to 0.7.0-alpha.2 or newer (ecosystem crates.io).