Chain Reactions: How Nonce Collisions in ECDSA Compromise Polygon MEV Searchers

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Madhwal, Yash, Seoev, Andrey, Della Pietra, Raffaele, Smirnova, Anastasiia, Yanovich, Yury
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910242047000576
author Madhwal, Yash
Seoev, Andrey
Della Pietra, Raffaele
Smirnova, Anastasiia
Yanovich, Yury
author_facet Madhwal, Yash
Seoev, Andrey
Della Pietra, Raffaele
Smirnova, Anastasiia
Yanovich, Yury
contents ECDSA signatures form the bedrock of blockchain transaction authentication, yet their security critically depends on proper nonce generation. We uncover a critical vulnerability in the Polygon MEV ecosystem: systematic nonce reuse that enables complete private key recovery. Analyzing on-chain data reveals that searchers, driven by the need for sub-second response times in sealed-bid auctions, employ predictable nonce patterns. These patterns create linear relationships between signatures, allowing passive attackers to recover private keys using elementary algebra. We provide a compact linear-system formulation for such attacks, including the dangerous case of cross-wallet nonce collisions, and present concrete evidence of exploitable patterns on Polygon. Our findings demonstrate how protocol-induced latency pressures can lead to catastrophic cryptographic failures in production blockchain systems, where a single implementation error compromises multiple accounts simultaneously.
format Preprint
id arxiv_https___arxiv_org_abs_2605_21498
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Chain Reactions: How Nonce Collisions in ECDSA Compromise Polygon MEV Searchers
Madhwal, Yash
Seoev, Andrey
Della Pietra, Raffaele
Smirnova, Anastasiia
Yanovich, Yury
Cryptography and Security
ECDSA signatures form the bedrock of blockchain transaction authentication, yet their security critically depends on proper nonce generation. We uncover a critical vulnerability in the Polygon MEV ecosystem: systematic nonce reuse that enables complete private key recovery. Analyzing on-chain data reveals that searchers, driven by the need for sub-second response times in sealed-bid auctions, employ predictable nonce patterns. These patterns create linear relationships between signatures, allowing passive attackers to recover private keys using elementary algebra. We provide a compact linear-system formulation for such attacks, including the dangerous case of cross-wallet nonce collisions, and present concrete evidence of exploitable patterns on Polygon. Our findings demonstrate how protocol-induced latency pressures can lead to catastrophic cryptographic failures in production blockchain systems, where a single implementation error compromises multiple accounts simultaneously.
title Chain Reactions: How Nonce Collisions in ECDSA Compromise Polygon MEV Searchers
topic Cryptography and Security
url https://arxiv.org/abs/2605.21498