Thread

Replies (36)

Whirlpool is a ZeroLink implementation similar to Wasabi Wallet 1.x was and even when the protocol and the cryptography involved are simple, there are many chances to make mistakes. During the early days Wasabi team introduced bugs using RSA and then using Schnorr, for example. This is something to celebrate anyway as we need more privacy tools and because it was sad to witness the level of cowardy raining in the environment while a bunch of "purists" attacked all privacy tools as if they were able to do it better.
🛡️
this guy only repeats stuff that fits his bias, without understanding them himself. nobody has had time to thoroughly review Ashigarus Whirlpool implementation yet. so far it's clear they have done some work to fix that vulnerability.
And now, if the coordinator signs outputs with the same static blind key in all rounds, an attacker can accumulate those signatures and redeem them later to register additional outputs without contributing new inputs. It does not allow them to steal funds, but it breaks the round balances and causes it to fail, blocking all other participants (DoS). And on top of that, they don't mitigate the vulnerability they've tried to remedy with this crap... If they were at least humble, they would get help... View quoted note →