Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Ripple CEO Reveals Why Banks Aren’t Embracing XRP at Scale

June 16, 2026

BTC Holds Firm Above $66K: Sustainable Rally or Temporary Relief? (June 2026)

June 16, 2026

‘Time to Revisit’ US Accredited Investor Laws

June 16, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Blockchain

Besu’s BN254 Vulnerability: Subgroup Check Flaw Exposes Security Risks

By WebDeskMay 25, 20253 Mins Read
Besu’s BN254 Vulnerability: Subgroup Check Flaw Exposes Security Risks
Share
Facebook Twitter LinkedIn Pinterest Email


Iris Coleman
May 25, 2025 14:56

A critical vulnerability in Besu’s Ethereum client related to subgroup checks on BN254 curve has been addressed. This flaw could have potentially compromised cryptographic security.





Besu, an Ethereum execution client, recently faced a significant security vulnerability due to improper subgroup checks on the BN254 elliptic curve, as detailed in a report from the Ethereum Foundation. This flaw, identified in version 25.2.2 of Besu, posed a risk to the consensus mechanism by allowing potential manipulation of cryptographic operations.

Understanding the BN254 Curve

The BN254 curve, also known as alt_bn128, is an elliptic curve used within Ethereum for cryptographic functions. It was the sole pairing curve supported by the Ethereum Virtual Machine (EVM) before the introduction of EIP-2537. This curve is critical for operations defined under EIP-196 and EIP-197 precompiled contracts, which facilitate efficient computation on the curve.

Vulnerability Insights

A notable security concern in elliptic curve cryptography is the invalid curve attack, which exploits points not lying on the correct curve. Such vulnerabilities are especially concerning for non-prime order curves like BN254 used in pairing-based cryptography. Ensuring that a point belongs to the correct subgroup is essential, as failure to do so can lead to security breaches.

In Besu’s case, the vulnerability arose because the subgroup membership check was performed before verifying if the point was on the curve. This sequence error could allow a point within the correct subgroup but off the curve to bypass security checks, potentially compromising the system’s integrity.

Technical Explanation and Solution

To determine if a point P is valid, it must be confirmed that it lies on the curve and is in the correct subgroup. The flaw in Besu’s implementation skipped the curve check, a critical oversight. The proper validation process involves checking both the curve and subgroup membership, typically by multiplying the point by the subgroup’s prime order and verifying it results in the identity element.

The Ethereum Foundation’s report highlighted that the issue was promptly addressed by the Besu team, with a fix implemented in version 25.3.0. The correction ensures that both checks are conducted in the appropriate order, safeguarding against potential exploits.

Broader Implications and Security Practices

Although this flaw was specific to Besu and did not affect other Ethereum clients, it underscores the importance of consistent cryptographic checks across different software implementations. Discrepancies can lead to divergent client behavior, threatening network consensus and trust.

This incident highlights the critical need for rigorous testing and security measures in blockchain systems. Initiatives like the Pectra audit competition, which helped surface this issue, are vital for maintaining the ecosystem’s resilience by encouraging comprehensive code reviews and vulnerability assessments.

The Ethereum Foundation’s proactive approach and the swift response from the Besu team demonstrate the importance of collaboration and vigilance in maintaining the integrity of blockchain systems.

Image source: Shutterstock


Credit: Source link

Previous ArticleHow James Wynn Became Crypto’s Boldest Whale on Hyperliquid
Next Article What To Expect From BTCfi & L2s Companies At Bitcoin 2025

Related Posts

Top Projects from Anthropic Opus 4.7 Hackathon Announced

June 15, 2026

Standard Chartered Says Bitcoin (BTC) Bottom May Be In

June 15, 2026

Strategy Buys 1,587 BTC for $100M, Lowers Average Cost Basis

June 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ripple CEO Reveals Why Banks Aren’t Embracing XRP at Scale

June 16, 2026

BTC Holds Firm Above $66K: Sustainable Rally or Temporary Relief? (June 2026)

June 16, 2026

‘Time to Revisit’ US Accredited Investor Laws

June 16, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Bittensor Benefits as Anthropic Faces Regulatory Scrutiny

BlackRock’s Bitcoin income ETF BITA begins trading on June 16

Top Projects from Anthropic Opus 4.7 Hackathon Announced

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$66,155.00-0.64%
  • ethereumEthereum(ETH)$1,804.560.60%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$612.41-2.42%
  • rippleXRP(XRP)$1.240.22%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$74.512.02%
  • tronTRON(TRX)$0.317561-1.07%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.27%
  • HyperliquidHyperliquid(HYPE)$76.3112.18%
  • dogecoinDogecoin(DOGE)$0.087929-2.35%
  • USDSUSDS(USDS)$1.000.00%
  • leo-tokenLEO Token(LEO)$9.76-0.29%
  • RainRain(RAIN)$0.0139282.68%
  • zcashZcash(ZEC)$510.39-4.05%
  • stellarStellar(XLM)$0.2251799.94%
  • cardanoCardano(ADA)$0.178901-4.01%
  • whitebitWhiteBIT Coin(WBT)$54.550.52%
  • moneroMonero(XMR)$339.82-1.49%
  • CantonCanton(CC)$0.163755-0.33%
  • chainlinkChainlink(LINK)$8.35-0.18%
  • USD1USD1(USD1)$1.00-0.03%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.67-5.67%
  • bitcoin-cashBitcoin Cash(BCH)$220.23-2.88%
  • daiDai(DAI)$1.000.02%
  • LABLAB(LAB)$13.0132.19%
  • MemeCoreMemeCore(M)$3.105.95%
  • hedera-hashgraphHedera(HBAR)$0.0828980.14%
  • litecoinLitecoin(LTC)$45.44-0.91%
  • suiSui(SUI)$0.79-2.26%
  • nearNEAR Protocol(NEAR)$2.41-2.73%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • avalanche-2Avalanche(AVAX)$6.930.00%
  • shiba-inuShiba Inu(SHIB)$0.000005-1.78%
  • crypto-com-chainCronos(CRO)$0.062207-0.84%
  • paypal-usdPayPal USD(PYUSD)$1.000.01%
  • Global DollarGlobal Dollar(USDG)$1.000.03%
  • tether-goldTether Gold(XAUT)$4,324.60-0.08%
  • BittensorBittensor(TAO)$265.20-4.91%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • worldcoin-wldWorldcoin(WLD)$0.655.16%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.08%
  • pax-goldPAX Gold(PAXG)$4,335.280.02%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.060132-1.69%
  • uniswapUniswap(UNI)$3.0513.85%
  • mantleMantle(MNT)$0.58-1.88%
  • OndoOndo(ONDO)$0.379680-0.49%
  • AsterAster(ASTER)$0.673.66%
  • polkadotPolkadot(DOT)$1.03-0.34%