CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

Besu’s BN254 Vulnerability: Subgroup Check Flaw Exposes Security Risks

May 25, 2025
in Blockchain
Reading Time: 2 mins read
A A
0
Ethereum’s Highly Awaited “London Hard Fork” Is Now Alive
0
SHARES
4
VIEWS
ShareShareShareShareShare


Iris Coleman
May 25, 2025 14:56

A critical vulnerability in Besu’s Ethereum client related to subgroup checks on BN254 curve has been addressed. This flaw could have potentially compromised cryptographic security.





Besu, an Ethereum execution client, recently faced a significant security vulnerability due to improper subgroup checks on the BN254 elliptic curve, as detailed in a report from the Ethereum Foundation. This flaw, identified in version 25.2.2 of Besu, posed a risk to the consensus mechanism by allowing potential manipulation of cryptographic operations.

Understanding the BN254 Curve

The BN254 curve, also known as alt_bn128, is an elliptic curve used within Ethereum for cryptographic functions. It was the sole pairing curve supported by the Ethereum Virtual Machine (EVM) before the introduction of EIP-2537. This curve is critical for operations defined under EIP-196 and EIP-197 precompiled contracts, which facilitate efficient computation on the curve.

Vulnerability Insights

A notable security concern in elliptic curve cryptography is the invalid curve attack, which exploits points not lying on the correct curve. Such vulnerabilities are especially concerning for non-prime order curves like BN254 used in pairing-based cryptography. Ensuring that a point belongs to the correct subgroup is essential, as failure to do so can lead to security breaches.

In Besu’s case, the vulnerability arose because the subgroup membership check was performed before verifying if the point was on the curve. This sequence error could allow a point within the correct subgroup but off the curve to bypass security checks, potentially compromising the system’s integrity.

Technical Explanation and Solution

To determine if a point P is valid, it must be confirmed that it lies on the curve and is in the correct subgroup. The flaw in Besu’s implementation skipped the curve check, a critical oversight. The proper validation process involves checking both the curve and subgroup membership, typically by multiplying the point by the subgroup’s prime order and verifying it results in the identity element.

The Ethereum Foundation’s report highlighted that the issue was promptly addressed by the Besu team, with a fix implemented in version 25.3.0. The correction ensures that both checks are conducted in the appropriate order, safeguarding against potential exploits.

Broader Implications and Security Practices

Although this flaw was specific to Besu and did not affect other Ethereum clients, it underscores the importance of consistent cryptographic checks across different software implementations. Discrepancies can lead to divergent client behavior, threatening network consensus and trust.

This incident highlights the critical need for rigorous testing and security measures in blockchain systems. Initiatives like the Pectra audit competition, which helped surface this issue, are vital for maintaining the ecosystem’s resilience by encouraging comprehensive code reviews and vulnerability assessments.

The Ethereum Foundation’s proactive approach and the swift response from the Besu team demonstrate the importance of collaboration and vigilance in maintaining the integrity of blockchain systems.

Image source: Shutterstock


Credit: Source link

RELATED POSTS

Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

Riot Platforms Sells $289M in Bitcoin as Mining Output Drops 4% in Q1

Exploring Chainlink’s Role Beyond Price Feeds in the Blockchain Ecosystem

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

Ripple CEO Brad Garlinghouse Explores the Role and Importance of Crypto ETFs

Next Post

Bitcoin’s Moonshot: Fundstrat’s Tom Lee Sees $1M–$1.5M Target in Play

Related Posts

Bitcoin Addresses Holding Between 100 and 10,000 BTC Hit a 7-Week High
Blockchain

Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

April 10, 2026
Riot Blockchain Yearly Bitcoin Production Increases by 236%, Accumulates $194M in BTC
Blockchain

Riot Platforms Sells $289M in Bitcoin as Mining Output Drops 4% in Q1

April 2, 2026
Galaxy Digital: Ethereum Developers Discuss Key Upgrades During Latest Consensus Call
Blockchain

Exploring Chainlink’s Role Beyond Price Feeds in the Blockchain Ecosystem

December 9, 2025
Next Post
Bitcoin’s Moonshot: Fundstrat’s Tom Lee Sees $1M–$1.5M Target in Play

Bitcoin’s Moonshot: Fundstrat’s Tom Lee Sees $1M–$1.5M Target in Play

Bessent: Biden ‘Starved’ Crypto—Trump’s Plan Could Flood Treasuries With Trillions

Bessent: Biden ‘Starved’ Crypto—Trump’s Plan Could Flood Treasuries With Trillions

Recommended Stories

Can US-Iran new peace deal signal keep Bitcoin above $70,000?

Can US-Iran new peace deal signal keep Bitcoin above $70,000?

April 8, 2026
Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

April 8, 2026
Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

April 14, 2026

Popular Stories

  • Winklevoss Twins Continue Crypto Donation Spree With Another $1,000,000 in Bitcoin (BTC)

    Trader Says DeFi Altcoin Aave Witnessing Clear Trend Switch, Updates Forecast on Two Low-Cap Coins

    0 shares
    Share 0 Tweet 0
  • Restaking Reshapes Crypto Trust With A Shared Security Model

    0 shares
    Share 0 Tweet 0
  • Georgia Secures $100M Partnership to Advance Tokenized Real‑World Asset (RWA) Agriculture

    0 shares
    Share 0 Tweet 0
  • The Sandbox Q2 2023 Report: 59% Increase in NFT Mints, 52% Rise in Primary Sales, 15% Fall in Revenue in Q2

    0 shares
    Share 0 Tweet 0
  • Ethereum Team Leader Critiques University’s Apathy Towards Crypto Education

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
  • SEC Opens Proceedings on NYSE Proposal to List Grayscale Crypto ETF Options – Regulation Bitcoin News
  • Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.