A cryptography article has raised new questions about the transparency of the SEC 2 Koblitz curve parameter selection process, including for secp256k1, the elliptic curve used by Bitcoin. The report says a reproducible experiment on the standard generator point G found that dividing the point by 2 yields an unusually short x-coordinate with a shared 152-bit hexadecimal substring that also appears across secp160k1, secp192k1, secp224k1, and secp256k1. The article attributes the observation to earlier work by John Zweng and argues the repeated structure is more consistent with a deterministic but undocumented generation method than with random selection.
The report does not claim a direct break of ECDSA or Schnorr signatures when a single generator is used, but says the finding could affect confidence in how standardized curve parameters were chosen. It highlights potential implications for future multi-generator cryptographic constructions, including Pedersen commitments and confidential transaction designs, where transparent NUMS-style parameter generation is important to avoid hidden structure. The article also says the anomaly can be reproduced with Python and SageMath and appears specific to division by 2 rather than small divisors such as 3, 5, or 7.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-27, Polynonce published a technical article arguing that claims of '12 hidden prime numbers' embedded in secp256k1 constants are not mathematically supported. The article reports direct checks of SEC2 parameters and concludes the theory is pseudoscientific numerology rather than evidence of a cryptographic backdoor.
On 2026-07-27, Polynonce published a Russian-language technical article arguing that secp256k1's parameters were selected deterministically rather than randomly. The article claims 12 hidden prime divisors can be derived from key secp256k1 constants and provides Python, SageMath, Magma, and PARI/GP scripts to inspect and factor those values.
The Polynonce article says John Zweng's 2025 work identified that dividing the standard generator point G by 2 on secp160k1, secp192k1, secp224k1, and secp256k1 yields x-coordinates sharing a common 152-bit hexadecimal substring, suggesting a deterministic but undocumented generator selection process.
On 2026-07-26, Polynonce published an article analyzing the SEC 2 Koblitz curves and reproducing the claimed anomaly with Python and SageMath/Google Colab, while arguing the finding raises transparency concerns for Certicom's parameter generation and future multi-generator cryptographic constructions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
10 references tracked. Mallory keeps watching after this page renders.
polynonce.ru
Open sourcepolynonce.ru
Open sourcepolynonce.ru
Open sourcepolynonce.ru
Open sourcepolynonce.ru
Open sourcegithub.com
Open sourcebitcolab.ru
Open sourcesecg.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.