This release adds 4 notable features for engineering teams evaluating rollout.
Published 5mo
MCP Security & Auth
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai-agents
ai-security
bitcoin
cryptography
custody
ecdsa
+10 more
high-risk
java
key-management
kms
mpc
schnorr
taproot
threshold-cryptography
threshold-signatures
tss
Affected surfaces
auth
Summary
AI summaryImproved Byzantine availability by excluding dead nodes and imposters, added explicit reporting of them, and persisted DKG commitments to drive Y_i derivation.
Full changelog
- Improved availability in Byzantine flows by automatically excluding dead nodes and detected imposters from subsequent quorums.
- Added explicit reporting of
impostersin responses and audit logs, anddeadnodes in audit logs for post-mortem analysis. - Persisted DKG commitments during key generation and used them as the source of truth for deriving
Y_iin ECIES and FROST flows. ThresholdSignatureandDecryptedresponses now include animpostersfield.
See Detecting Imposters for more details.
Recommended actions
- Run a key
REFRESHfor keys used in ECIES and FROST signatures so nodes deriveY_ifrom stored DKG commitments.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About TKeeper
All releases →Related context
Beta — feedback welcome: [email protected]