Repository navigation
v0.9.3
● Fix: signal message tamper check crash (~55% of messages)
Condition 5 of the Signal spend handler was using scalar.from_bytearray_big_endian to convert the blake2b_256 message digest into a BLS12-381 scalar. Since
blake2b_256 produces 256-bit values and the scalar field prime r is ~255 bits, roughly 55% of all possible messages produce a hash ≥ r, causing
from_bytearray_big_endian to return None and crash the validator via a failed expect.
The fix replaces that with builtin.bytearray_to_integer(...) % scalar.field_prime, which reduces the digest directly into the scalar field — the same reduction the
circom circuit applies implicitly when receiving signalHash as a public input, keeping both sides consistent.