Reportssign-02

BiT (sign-02)

CandidateBiT
FamilyLattice-based
ArchiveBiT.zip (SHA-256: 698fbe834279a4100a66c20f3e0b634c738e1150936acf74b55efc6db6975e8d)

sign-02-1: A 512-bit unsalted message representative caps forgery security at 256 bits

ClassificationCritical / design
StatusConfirmed
AffectedBiT-512 specification and reference implementation
DiscoveryTrivial
ExploitationApproximately 2^256 hash evaluations
CreditMarkku-Juhani O. Saarinen markku-juhani.saarinen@tuni.fi, with AI assistance
Date2026-09-21

BiT-512 claims 512-bit classical security and normatively computes the message representative mu = H(tr || M) as a 512-bit value. This fixed unsalted representative has only 256 bits of generic collision resistance.

After finding distinct messages with the same mu, an attacker requests a signature on one and transfers it unchanged to the other. Later signing randomness cannot distinguish the already-colliding messages. The reference implementation uses the same 64-byte representative.

This is a specification-level design break of the advertised 512-bit classical EUF-CMA level. It is a generic 2^256 security ceiling, not a computation performed by the harness.

Reproducing

Commands below run in a checkout of the ngcc-harness repository with the candidate built (see its README).

python3 security/design_parameter_audit.py

The check verifies the normative BiT-512 construction on physical PDF pages 18 and 33–34 and the 64-byte source constant.