4 ms·
You can't derive an secp256k1 privkey from the associated pubkey. That's the whole point.
by BigParm 2y ago
You can't derive an secp256k1 privkey from the associated pubkey. That's the whole point.
- fidelramos 2y agoYou are right in the general case. But the public key is included in a transaction when it gets signed, and in this particular case the attackers already had part of the private key, that's what allowed a different attacker to combine both pieces and break the private key quickly.