Unknown · Ultrafastsecp256K1 · CVE-2026-55174
**Name of the Vulnerable Software and Affected Versions**
UltrafastSecp256k1 versions prior to 4.2.0
**Description**
The ECDSA adaptor pre-signature verification in UltrafastSecp256k1 accepts forged adaptor pre-signatures. This occurs because the `r` value is not cryptographically bound to the adaptor point `T` due to a missing DLEQ binding. DLEQ binding is a cryptographic proof that ensures a secret key used in one context is the same as the one used in another.
**Recommendations**
Update to version 4.2.0.