github.com/iofinnet/thresh, github.com/thorchain/thorchain-tss and github.com/bnb-chain/tss-lib are vulnerable to Timing Attacks. The vulnerability exists due to a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic which allows an attacker to gain sensitive information.
github.com/advisories/GHSA-3w84-4mjc-rjw7
github.com/bnb-chain/tss-lib/blob/v1.3.5/ecdsa/keygen/round_2.go#L22
github.com/bnb-chain/tss-lib/tree/v1.3.5
github.com/IoFinnet/threshlib/blob/master/ecdsa/keygen/round_2.go#L19
github.com/IoFinnet/tss-lib/releases/tag/v2.0.0
gitlab.com/thorchain/tss/tss-lib/-/blame/master/ecdsa/keygen/round_2.go#L22
gitlab.com/thorchain/tss/tss-lib/-/tags/v0.1.3
medium.com/%40iofinnet/security-disclosure-for-ecdsa-and-eddsa-threshold-signature-schemes-4e969af7155b
medium.com/@iofinnet/security-disclosure-for-ecdsa-and-eddsa-threshold-signature-schemes-4e969af7155b