Hermes / Sign & Forge

Sign & Forge

A signature proves you hold a private key without ever showing it. Every signature needs a fresh secret nonce k. Reuse k just once across two messages and your private key drops out by schoolbook algebra. It is the bug that unlocked the PlayStation 3 and has drained real wallets.

1 · Sign & verify

z =– r =– s =–
not signed yet

2 · The attack: one nonce, two messages

shared r =– s₁ =– s₂ =–

Your key pair

pubkey x–

The signatures below are made with this key. The attack never sees it, yet it recovers it exactly.

Why it works

Each signature is s = k⁻¹(z + r·d). The nonce k is the only secret hiding d. Two signatures with the same r betray that they share k: two equations, two unknowns, solved.

Things to notice

Edit after signing → invalid

A signature is bound to one exact message. Change a single character and verification fails immediately. You can't lift a signature onto different terms.

Reused nonce = shared r

Because r comes only from k·G, two signatures sharing a nonce share their r. That repeat is the visible fingerprint of the fatal mistake.

It really recovers your key

The recovered d matches the private key in the side panel to the last digit, computed only from public signature data.