A rollback that leaks a threshold key share
Trail of Bits shows how MPC inside a TEE can backfire: an untrusted host restores a used pre-signature, and the signer reuses its nonce.
2 minSmart Contract AuditsFresh · 25 Sept
Threshold signing is increasingly deployed inside trusted execution environments on the theory that the two protections stack: multi-party computation spreads trust across parties, while the TEE roots it in the hardware maker's attestation. Drawing on audit work, Paul Bottinelli of Trail of Bits argues the pairing is worth having only if the TEE is treated as defence in depth rather than a substitute for a sound protocol.
The rollback
His central example concerns pre-signatures, the nonce commitments that Schnorr and ECDSA threshold schemes compute in advance to speed up signing. Reusing one leaks the signer's private share. Some implementations store pre-signatures on disk and delete each after use. Inside a TEE, however, the host is explicitly untrusted and still controls storage. It can roll the filesystem back after the deletion and hand the used pre-signature back to the enclave, so the signer reuses its nonce share and discloses its key share. Beyond that case, the post lists the pitfalls it meets most often:
- Incomplete attestation measurements, such as tools fetched at runtime that were never measured.
- Verification steps skipped because each vendor defines them differently.
- Stale backups served by the host: authenticated encryption gives integrity, not freshness.
- Physical attacks, including an interposer costing under $200 that silently drops DDR5 writes.
- Defaults such as Intel tools letting known-vulnerable firmware pass attestation for a year after disclosure.
Behind them sits a clash of trust models: MPC exists to avoid a single point of trust, and a TEE concentrates trust in its manufacturer. If every party runs on the same vendor's hardware or the same cloud, the distribution MPC was meant to provide becomes nominal.
The recommendations follow from this. Bind attestations to the identities of the MPC parties, terminate peer-to-peer channels inside the enclaves, implement every verification step the vendor requires, write constant-time code and, where the stakes justify the effort, spread parties across TEE vendors and cloud providers.
Retold from Trail of Bits. This is a summary in our own words; follow the link for the original reporting.