AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 37 Bitcoin

Merge pull request #552 from LedgerHQ/musig-pregen-nonces

Public commit record

What the developer wrote

Authored by Salvatore Ingala

73/100 · Adequate
Merge pull request #552 from LedgerHQ/musig-pregen-nonces

Allow pregenerating nonces for future MuSig2 signing
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how the Ledger Bitcoin app prepares nonces for MuSig2 multi-signature transactions. Previously, the nonce derivation included transaction-specific data, so a wallet had to know the exact transaction before asking the device for nonces. Now the nonces depend only on the wallet policy and input/key indexes, allowing a wallet to pre-generate nonces on one transaction and later use them for a different transaction of the same wallet policy. The change is intentional and documented, but it narrows session identity to the wallet policy: only one pending signing session is allowed per wallet policy, and starting a new round 1 silently replaces the old one. The commit also adds a check that the pubnonce in the PSBT matches the one the device would recompute, so a replaced session fails cleanly in round 2.

Recommended action

Treat this as a deliberate protocol-level behavior change rather than a vulnerability. Reviewers and integrators should ensure wallet software understands the new semantics: pubnonces are bound to wallet policy and input/key index, not to a specific PSBT, and a second round 1 for the same wallet policy invalidates any prior pending round 2. Wallet implementations should guard against accidental session replacement and should never reuse pubnonces across different wallet policies or after a failed round 2. No immediate patch is required unless the documented behavior is found to violate BIP-327 security assumptions.

Security signals we found

01

MuSig2 nonce derivation made transaction-independent by design

02

psbt_session_id now depends only on wallet policy, not transaction hashes

03

Single pending session per wallet policy enforced by session replacement

04

New round-2 pubnonce equality check prevents signing with stale or mismatched nonces

05

explicit_bzero added for signing state, cache, and MuSig session state after flow

06

Tests added for cross-transaction nonce reuse, session replacement, wrong pubnonce rejection, and single-use session behavior

Risk score

Why this scored 37/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.