Skip to content

fix(sdk-core): bind EdDSA MPCv1 external signer signing state - #9857

Open
danielpeng1 wants to merge 1 commit into
masterfrom
WCN-2112/eddsa-mpcv1-bind-signing-nonce
Open

danielpeng1 wants to merge 1 commit into
masterfrom
WCN-2112/eddsa-mpcv1-bind-signing-nonce

Conversation

@danielpeng1

@danielpeng1 danielpeng1 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Hardens the EdDSA MPCv1 external signer signing flow.

  • Encrypted signing state is now tied to the transaction request it was created for, and to BitGo's commitment
  • A signing nonce can no longer be reused for a different signing attempt
  • The G share step uses the signer's own encrypted state instead of a caller-supplied R share

Breaking change
Only affects EdDSA MPCv1 wallets using BitGo Express external signing, or custom R/G share generators:

  • R share: now requires bitgoToUserCommitment, and also returns encryptedUserToBitgoRShare
  • G share: takes encryptedUserToBitgoRShare (returned by the R step) instead of userToBitgoRShare

The BitGo Express instance and its external signer must run the same version (noted in EXTERNAL_SIGNER.md).

Testing

  • Unit tests for mismatched transaction requests, mismatched or missing commitments, and nonce reuse
  • The existing Express external signer end-to-end test still produces a valid signature

Ticket: WCN-2112

Bind the encrypted signing state to its transaction request and the
BitGo commitment, and reject reusing a signing nonce across different
signing attempts.

BREAKING CHANGE: EdDSA MPCv1 external signer R share generation now
requires bitgoToUserCommitment and returns encryptedUserToBitgoRShare.
G share generation takes encryptedUserToBitgoRShare and
walletPassphrase instead of userToBitgoRShare.

Ticket: WCN-2112
@danielpeng1 danielpeng1 self-assigned this Sep 29, 2026
@linear-code

linear-code Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

WCN-2112

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Unit tests are failing on Node 26.x (Current release line, non-blocking). This is not an LTS version yet, so it does not block merge, but it signals an incompatibility to fix before Node 26.x becomes LTS.

View run

@danielpeng1
danielpeng1 requested a deployment to breaking-changes-override September 29, 2026 21:39 — with GitHub Actions Waiting
@danielpeng1
danielpeng1 marked this pull request as ready for review September 29, 2026 22:09
@danielpeng1
danielpeng1 requested review from a team as code owners September 29, 2026 22:09
})
),
/** User's R share sent to BitGo containing cryptographic commitments for EDDSA G share generation */
userToBitgoRShare: optional(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why we are removing it? it would break MPCv1 wallets?

This branch is waiting to be deployed

1 waiting deployment
breaking-changes-override — 529bc754 Waiting Sep 29, 2026 by danielpeng1 via Linter Override #5422
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants