Small, self-contained C implementation of Ristretto255 based on libdecaf
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Type Name Latest commit message Commit time
Failed to load latest commit information.
src Merge f_generic.c into f_arithmetic.c Aug 15, 2018
.travis.yml Adopt the Contributor Covenant (version 1.4) Aug 12, 2018

libristretto255 Build Status Appveyor Status

Experimental C implementation of Ristretto255, a prime order elliptic curve group created by applying the Decaf approach to cofactor elimination to Curve25519 (RFC 7748).

libristretto255 is based off of the libdecaf library by Mike Hamburg. For more information on Ristretto, please see the Ristretto web site:


This library is in an extremely early stage of development and is not ready to be used yet. Check back later for updates.

Known Issues

Travis CI

  • #24: Sporadic SEGV on Travis C with clang when running ristretto_gen_tables. This has been worked-around by enabling ASAN, but is probably indicative of deeper problems.


Copyright (c) 2014-2018 Ristretto Developers (, Cryptography Research, Inc (a division of Rambus).

Distributed under the MIT License. See LICENSE.txt for more information.