CVE-2023-33242
Lindell17 TSS Abort Mishandling
- Published
- Aug 9, 2023
- Updated
- Oct 10, 2024
- Assigning CNA
- Halborn
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NLow · next 30 days
- Percentile
- 72.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.
Sources
1Proof-of-concept exploit for CVE-2023-33242 demonstrating a bit extraction attack on the Lindell17 ECDSA protocol, enabling iterative private key recovery through abort mishandling.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.