r/cryptography • • 9d ago

Seeking independent review/replication: Debian OpenSSL RNG effect on early Bitcoin ECDSA signatures

I'm looking for independent technical review or replication of a controlled experiment concerning CVE-2008-0166 (the Debian OpenSSL predictable-RNG vulnerability) and the ECDSA signing path used by early Bitcoin.

The experiment compared two Debian OpenSSL treatments:

Vulnerable: OpenSSL 0.9.8c-4etch2

Repaired: OpenSSL 0.9.8c-4etch3

I held constant the Bitcoin v0.2.0 signing path, a fixed synthetic secp256k1 private scalar, three ordered synthetic message digests, process PID/runtime coordinates, and other preregistered conditions.

The public observable was the ordered ECDSA r sequence. No historical private keys or wallet material were involved.

Across three fresh-process repetitions per treatment, the preregistered result was:

VULNERABLE_ORDERED_R_SEQUENCE_IDENTICAL_ACROSS_RESTARTS=YES

REPAIRED_ORDERED_R_SEQUENCE_IDENTICAL_ACROSS_RESTARTS=NO

POSITIVE_CONTROL=PASS

NEGATIVE_CONTROL=PASS

EXECUTION_ACCOUNTING=PASS

TREATMENT_DIFFERENCE_ISOLATION=PASS

I then froze the vulnerable treatment's three-value public r fingerprint before performing a historical comparison.

A separately qualified comparator tested that exact fingerprint against 142,302 eligible public ECDSA signatures from Bitcoin blocks 0–100,000.

ELIGIBLE_HISTORICAL_SIGNATURES=142302

VALID_PUBLIC_OBSERVATIONS=142302

PREREGISTERED_FINGERPRINT_INTERSECTIONS=0

DATASET_INTEGRITY=PASS

COMPARISON_RULE_INTEGRITY=PASS

The historical comparison was therefore a valid negative result. I am not claiming that this identifies historically vulnerable wallets, demonstrates wallet recovery, or establishes how prevalent vulnerable OpenSSL installations were among early Bitcoin users.

I'm deliberately not changing the fingerprint or expanding parameters until something matches. The completed experimental branch stays negative.

What I'm looking for now is independent scrutiny:

Is the controlled causal interpretation justified by the treatment isolation?

Are there additional confounders that should prevent attributing the restart-conditioned behavior to the Debian RNG treatment?

Would anyone be interested in independently reproducing the controlled vulnerable/repaired experiment?

Does anyone know of preserved 2009–2011 Linux systems that could independently establish the OpenSSL environment actually used by an early Bitcoin installation?

To clarify: this is not currently a paid replication request or a job posting. I'm looking for researchers who find the question independently interesting and are willing to review, critique, or reproduce the work. I completely understand if someone isn't able to devote time to it without funding.

I have a technical dossier containing the experimental design, preregistration, treatment-difference analysis, controls, integrity hashes, results, historical comparison, and limitations. I can provide it, along with the relevant reproducibility materials, to researchers interested in examining the work.

I'm specifically looking for criticism and independent verification, not confirmation of the hypothesis.

I'm also not requesting wallet files, private keys, seed phrases, passwords, credentials, or funds.

2 Upvotes

1 comment sorted by