Papers1 provider · 2 records
September 28, 2020· IACR Transactions on Symmetric Cryptology
article
Open access

Cryptanalysis of Curl-P and Other Attacks on the IOTA Cryptocurrency

Authors:Ethan HeilmanNeha NarulaGarrett TanzerJames Peter Thomas. LovejoyMichael ColavitaMadars VirzaTadge Dryja

Abstract

We present attacks on the cryptography formerly used in the IOTA blockchain, including under certain conditions the ability to forge signatures. We developed practical attacks on IOTA’s cryptographic hash function Curl-P-27, allowing us to quickly generate short colliding messages. These collisions work even for messages of the same length. Exploiting these weaknesses in Curl-P-27, we broke the EUCMA security of the former IOTA Signature Scheme (ISS). Finally, we show that in a chosen-message setting we could forge signatures and multi-signatures of valid spending transactions (called bundles in IOTA).

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.