A critical cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK implementations and potential authentication bypass scenarios.
The vulnerability was located in the Peer.ts file of the TypeScript SDK, specifically in the processInitialRequest and processInitialResponse methods where signature data is prepared for BRC-104 mutual authentication.
Vulnerable Code Locations:
ts-sdk/src/auth/Peer.ts lines 527-531 (signing)ts-sdk/src/auth/Peer.ts lines 584-590 (verification)Root Cause: The TypeScript SDK incorrectly prepared signature data by:
message.initialNonce + sessionNoncebase64ToBytes(concatenatedString)This produced ~32-34 bytes of signature data instead of the correct 64 bytes.
Buggy Implementation (Before Fix):
// CRITICAL BUG: Concatenating base64 strings before decoding
data: Peer.base64ToBytes(message.initialNonce + sessionNonce)
Correct Implementation (After Fix): The fix properly decodes each base64 nonce individually, then concatenates the byte arrays:
data: [
...Peer.base64ToBytes(message.initialNonce),
...Peer.base64ToBytes(sessionNonce)
]
Why This is Critical: BRC-104 authentication relies on cryptographic signatures to establish mutual trust between peers. When signature data preparation is incorrect:
The cross-language test suite demonstrates this vulnerability:
Test Evidence:
// Buggy approach (produces ~32-34 bytes)
const concatenatedB64 = INITIAL_NONCE_B64 + SESSION_NONCE_B64;
const buggyResult = Array.from(Buffer.from(concatenatedB64, 'base64'));
// Correct approach (produces 64 bytes)
const correctResult = [...INITIAL_NONCE_BYTES, ...SESSION_NONCE_BYTES];
Base64 Padding Short Circuit Analysis:
The vulnerability occurs because base64 padding characters (=) act as early termination signals for base64 decoders. When concatenating base64 strings before decoding:
= padding character, producing only 32 bytes instead of 64Example with test data:
INITIAL_NONCE_B64: "QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUE=" (44 chars → 32 bytes)SESSION_NONCE_B64: "QkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkI=" (44 chars → 32 bytes)"QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUE=QkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkI="=)Vulnerability Type: Cryptographic signature verification bypass
Severity: Critical (CVSS 9.1 - Critical)
Affected Systems:
Who is Impacted:
Potential Attack Vectors:
The fix ensures all SDKs now produce identical cryptographic signatures, restoring proper mutual authentication across implementations.
{
"cwe_ids": [
"CWE-573"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-17T16:13:48Z",
"nvd_published_at": "2026-02-18T19:21:42Z",
"severity": "MODERATE"
}