A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2022; you can also visit the original URL.
The file type is
IACR Cryptology ePrint Archive
We present a sub-exponential forger by using a 𝑘-sum algorithm against the aggregate Γ-signature, which was proposed at AsiaCCS 2019 by Zhao. Our forger is a universal forger under a key-only attack and effective in the knowledge of secret key model. We also discuss the real impact of this attack in reality with Bitcoin applications. The discussions on the real impact of the attack also highlight the significant differences between the usage of individual signatures like EC-DSA and that ofdblp:journals/iacr/HanaokaOSSTZ20 fatcat:csvivl5e3nejhoq3uwer3qa2mm