AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 37 Bitcoin

Merge bitcoin-core/secp256k1#1933: refactor: introduce `ecmult_const_ge` helper (preventing accidential gej leaks)

Public commit record

What the developer wrote

Authored by merge-script

100/100 · Strong
Merge bitcoin-core/secp256k1#1933: refactor: introduce `ecmult_const_ge` helper (preventing accidential gej leaks)

02e00f54a0e0ac72c74eb4f5b84855b290bba124 test: refactor: simplify tests by using `_ecmult_const_ge` helper (Sebastian Falbesoner)
b4fbee61e91d30aedbe0e84f407393e0c27c8c55 refactor: rename `_ecmult_const` -> `_ecmult_const_gej` for consistency (Sebastian Falbesoner)
ace566f66c1b75d929c367612abf22944d81fb8e refactor: introduce `_ecmult_const_ge` helper (preventing accidental gej leaks) (Sebastian Falbesoner)

Pull request description:

This PR is the counterpart of #1861 for `_ecmult_const`: constant-time scalar multiplication with arbitrary points frequently involves a conversion to affine coordinates and clearing out the temporary Jacobian group element object after to avoid leaking secret key material, i.e. executing the following three functions:
* `secp256k1_ecmult_const(&rj, ...)`
* `secp256k1_ge_set_gej(&r, &rj)`
* `secp256k1_gej_clear(&rj)`

A helper `ecmult_const_ge` is introduced to deduplicate code and mitigate the risk that the last step is forgotten (which can easily happen, as it would not be detected by tests). It is applied in the ECDH and silentpayments modules.

The idea came up in the course of reviewing the DLEQ module, where a gej clearing was missing, see https://github.com/bitcoin-core/secp256k1/pull/1802#discussion_r3960829657.

ACKs for top commit:
real-or-random:
utACK 02e00f54a0e0ac72c74eb4f5b84855b290bba124

Tree-SHA512: dadfbace89875d50c331170738ebc413516a01d8b05a1e75a3d9c10ade194772633920a3ea0592c4b709cfb78b86a3bc72806e3f06f3ba5567a42e17ae1e2309
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit is a defensive code cleanup in Bitcoin Core's secp256k1 cryptography library. It introduces a helper function that automatically clears temporary secret data after a constant-time elliptic curve multiplication, and switches existing code to use it. The change prevents future mistakes where sensitive intermediate values could be left in memory, but the commit itself does not claim to fix an active vulnerability in the current code.

Recommended action

Treat as a hardening improvement rather than an urgent security patch. Review whether the DLEQ module and any other modules using `secp256k1_ecmult_const_gej` directly still perform proper `gej_clear` cleanup, since the commit explicitly notes that risk and references a prior missing-clear issue. Consider whether the new helper should be used in additional call sites to reduce future accidental leaks.

Security signals we found

01

Defensive refactoring to prevent accidental leakage of secret scalar information from Jacobian coordinates

02

New helper enforces memory clearing of intermediate group element after constant-time scalar multiplication

03

Adoption in ECDH and silentpayments modules, which process secret keys

04

Reference to a prior review finding of a missing gej_clear in a related DLEQ module

05

No direct bug fix or CVE claim in commit message or diff

Risk score

Why this scored 37/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 6/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.