Skip to content

v0.3.1 - Critical Ephemeral Key Bug Fix

Latest

Choose a tag to compare

@blocksorg blocksorg released this 04 Nov 06:45
· 3 commits to main since this release

Critical Bug Fix

This release fixes the root cause of MAC verification failures that occurred even with brand new accounts.

What Was Fixed

The ephemeral_key field in encrypted messages was incorrectly set to the sender's identity key instead of the actual ephemeral key generated during session establishment. This caused the sender and receiver to compute different shared secrets, resulting in MAC verification failures.

Changes

  • Added our_ephemeral_key field to Session struct to store the real ephemeral key
  • Updated establish_session() to store the ephemeral key during session creation
  • Updated encrypt_message() to include the real ephemeral key from the session
  • Both sender and receiver now use the same ephemeral key in DH operations, computing identical shared secrets

Impact

  • ✅ Fixes MAC verification failures for ALL accounts (new and existing)
  • ✅ Ensures proper X3DH key agreement protocol implementation
  • ✅ Both sender and receiver can now successfully decrypt messages

Installation

Download the appropriate binary for your platform below, make it executable, and run it.

🤖 Generated with Claude Code