Attacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature Scheme @HackersOnBoard
Attacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature Scheme  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 2 days ago
Our talk presents attacks on the cryptography used in the cryptocurrency IOTA, which is currently the 10th largest cryptocurrency with a market capitalization of 2.8 billion USD. IOTA is billed as a next generation blockchain for the Internet of Things (IoT) and claims partnerships with major companies in the IoT space such as Volkswagen and Bosch.

We developed practical differential cryptanalysis attacks on IOTA's cryptographic hash function Curl-P, allowing us to quickly generate short colliding messages of the same length. Exploiting these weaknesses in Curl-P, we break the EU-CMA security of the IOTA signature scheme. Finally, we show that in a chosen message setting we can forge signatures on valid IOTA payments. We present and demonstrate a practical attack (achievable in a few minutes) whereby an attacker could forge a signature on an IOTA payment, and potentially use this forged signature to steal funds from another IOTA user.

After we disclosed our attacks to the IOTA project, they patched the vulnerabilities presented in our research. However, Curl-P is still used in other parts of IOTA.
Attacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature SchemeDEF CON 27 - Elie Bursztein - How Deep Learning Is Revolutionizing Side-Channel CryptanalysisBlack Hat USA 2018 - Breaking the IIoT Hacking industrial Control GatewaysDEF CON 27 - Contests and Events - Contests Awards CeremonyDEF CON 27 - Ariel Herbert-Voss - Dont Red-Team AI Like a ChumpDEF CON 27 - How To Improve Coverage-Guided Fuzzing and Find New 0days in Tough TargetsMoney-rity Report Using Intelligence to Predict the Next Payment Card Fraud VictimsNone of My Pixel is Your Business Active Watermarking Cancellation Against Video Streaming ServiceBlack Hat USA 2018 - GOD MODE UNLOCKED - Hardware Backdoors in x86 CPUsFrom Workstation to Domain Admin Why Secure Administration isnt Secure and How to Fix itDEF CON 27 - Nikhil Mittal - RACE - Minimal Rights and ACE for Active Directory DominanceDEF CON 27 - finalphoenix - Rise of the Hypebots Scripting Streetwear
HackersOnBoard |

Attacks on the Curl-P Hash Function Leading to Signature Forgeries in the IOTA Signature Scheme

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER