{"id":"72b63c6b-73f8-4cb8-8636-76739d1dd2db","arxiv_id":"2605.21498","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Nonce reuse patterns in Polygon MEV searchers allow private-key recovery via linear algebra on ECDSA signatures.","lead":"The paper reports that MEV searchers on Polygon reuse ECDSA nonces in predictable patterns to meet sub-second auction deadlines, creating linear equations that let passive observers recover private keys from on-chain signatures. A smart generalist should read it because it shows how real-world speed pressures can turn a known theoretical weakness into an actual, scalable attack on live blockchain infrastructure.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.3","headline":"Nonce pattern persistence and frequency not quantified enough to confirm reliable multi-signature collection for linear solve","rationale":"The reader's weakest assumption matches the empirical robustness issue exactly; the full text does not appear to close this gap with quantitative persistence metrics, so the verdict should remain conditional on further verification of real-world exploitability rather than moving to accept or reject.","tokens_in":1620,"tokens_out":326,"duration_ms":45379,"concrete_test":"Re-analyze the paper's on-chain dataset: for each searcher address with ≥5 signatures, group by nonce relationship (same k or k2 = a·k1 + b), count solvable clusters per address, and check whether ≥70% of addresses yield a full-rank linear system whose solved private key validates all signatures in its cluster via the standard ECDSA verification equation.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The central claim requires that observed predictable nonce patterns (including cross-wallet collisions) occur systematically and repeatedly on the same searcher addresses so that a passive observer can accumulate enough related signatures to set up and solve the linear system for the private key. While the paper reports concrete on-chain patterns, the load-bearing gap is the absence of explicit counts or time-series data showing how often a given address produces a solvable cluster (e.g., at least two signatures with identical or linearly related nonces) within a short enough window that the searcher has not yet rotated keys or altered behavior. Without this, the elementary-algebra recovery remains possible in principle but not demonstrated as reliably actionable in production MEV traffic.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper claims that MEV searchers on Polygon employ predictable nonce patterns in ECDSA signatures due to sub-second latency requirements in sealed-bid auctions. These patterns, including cross-wallet nonce collisions, create linear relationships between signatures that allow passive attackers to recover private keys using elementary algebra. The work provides a compact linear-system formulation for such attacks and presents concrete on-chain evidence of exploitable patterns.","tokens_in":1769,"tokens_out":397,"duration_ms":34498,"significance":"If the central claims hold, the results illustrate how protocol-induced pressures for rapid responses can induce catastrophic cryptographic failures in live blockchain systems, with a single implementation error potentially compromising multiple accounts. Strengths include the elementary-algebra recovery method, the explicit treatment of cross-wallet collisions, and the grounding in on-chain observations that support falsifiable predictions.","major_comments":[{"comment":"The section presenting on-chain evidence reports concrete nonce patterns but does not include explicit counts, frequencies, or time-series statistics showing how often a given searcher address produces a solvable cluster (at least two signatures with identical or linearly related nonces) within a short enough window before key rotation. This quantification is load-bearing for the claim that such attacks are reliably actionable against production MEV traffic.","section":null},{"comment":"In the linear-system formulation, the minimum number of signatures required for a unique solution in the cross-wallet collision case, together with any assumptions on the exact linear dependence of the nonces, should be stated explicitly so that readers can assess the practical threshold for key recovery.","section":null}],"minor_comments":[{"comment":"Clarify the dataset exclusion criteria and any filtering applied to the on-chain transactions to support reproducibility.","section":null},{"comment":"Ensure all equations in the linear-system section are numbered and cross-referenced in the surrounding text.","section":null}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for their detailed review and constructive comments on our manuscript. We have carefully considered each major comment and provide point-by-point responses below. We believe these revisions will enhance the clarity and impact of our work.","responses":[{"response":"We agree that additional quantitative analysis would strengthen the presentation of our on-chain evidence. In the revised version of the manuscript, we will augment the on-chain evidence section with explicit counts of solvable clusters for each searcher address, frequencies of nonce collision events, and time-series statistics demonstrating the occurrence of such clusters within short time windows prior to key rotation. These additions will be derived from our existing dataset of Polygon MEV transactions and will directly support the actionability of the attacks in production settings.","revision_made":"yes","referee_comment":"The section presenting on-chain evidence reports concrete nonce patterns but does not include explicit counts, frequencies, or time-series statistics showing how often a given searcher address produces a solvable cluster (at least two signatures with identical or linearly related nonces) within a short enough window before key rotation. This quantification is load-bearing for the claim that such attacks are reliably actionable against production MEV traffic."},{"response":"We thank the referee for highlighting this point for improved clarity. In the revised manuscript, we will explicitly state in the linear-system formulation section that, under the assumption of linear dependence between nonces (such as identical nonces or proportional relations arising from deterministic generation patterns), a minimum of two signatures is required to obtain a unique solution for the private key in the cross-wallet collision case. We will also detail the specific assumptions on the linear dependence relations used in our formulation.","revision_made":"yes","referee_comment":"In the linear-system formulation, the minimum number of signatures required for a unique solution in the cross-wallet collision case, together with any assumptions on the exact linear dependence of the nonces, should be stated explicitly so that readers can assess the practical threshold for key recovery."}],"tokens_in":1244,"tokens_out":435,"duration_ms":41983,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The main point here is that some Polygon MEV searchers are generating ECDSA nonces in predictable ways that create linear relationships across signatures, letting a passive observer recover private keys with basic algebra. The paper backs this with on-chain observations and includes the cross-wallet collision case, which is a useful addition to the usual same-wallet reuse scenario. They also give a compact linear-system formulation that keeps the attack description straightforward. That part is new: the first reported measurement of these patterns specifically inside Polygon MEV activity rather than just restating the classic nonce reuse attack. The context around latency pressure in sealed-bid auctions helps explain why the bad patterns appear in production. The math itself is elementary and does not rely on any exotic assumptions, which makes the claim easy to check. The soft spot is the missing quantification on how often a single searcher address actually produces enough related signatures in a short window. The central claim needs those patterns to repeat reliably so an attacker can collect the signatures before any key change. Without counts or time-series data on cluster frequency, the practical risk stays possible in principle but not fully demonstrated as routine. The on-chain evidence is external rather than fitted, which avoids circularity, but the dataset details and exclusion rules would need to be solid for referees to judge selection effects. This is for people working on blockchain security, MEV infrastructure, or ECDSA implementations under real-time constraints. A reader who wants concrete examples of how speed requirements break cryptographic assumptions would find it useful. I would send it to peer review because the empirical angle is worth checking and the formulation is clear enough that referees can focus on the data and attack feasibility rather than starting from scratch.","headline":"The paper documents real nonce reuse patterns in Polygon MEV searchers with on-chain examples and a clean linear recovery setup, but leaves the frequency of solvable clusters unquantified.","tokens_in":2239,"tokens_out":416,"would_cite":false,"duration_ms":34715,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":{"model":"grok-4.3","evidence":[],"headline":"ECDSA nonce-reuse linear algebra in MEV has no structural overlap with RS cost or forcing machinery","alignment":"orthogonal","rationale":"Paper's central construction is standard modular linear algebra over nonce relations (Cases C1–C3, eqs. 2–3) to recover ECDSA private keys from observed signature patterns on Polygon. RS framework (reality_from_one_distinction, J-cost uniqueness, phi-ladder constants, 8-tick/D=3 forcing) contains no cryptographic primitives, signature schemes, or nonce analysis; the two domains share neither theorems nor structural motifs.","tokens_in":41932,"confidence":"high","tokens_out":143,"duration_ms":11852,"cache_read_input_tokens":32896,"cache_creation_input_tokens":0},"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"Systematic nonce reuse in ECDSA signatures allows recovery of private keys for Polygon MEV searchers.","keywords":["ECDSA","nonce reuse","private key recovery","MEV","Polygon","blockchain security","signature analysis","cryptographic vulnerability"],"falsifier":"Collecting additional on-chain signatures from the same Polygon MEV searcher and verifying whether solving the linear system consistently recovers a private key that matches the observed public key.","tokens_in":2532,"feed_emoji":"🔓","tokens_out":550,"duration_ms":46219,"temperature":0.7,"pith_summary":"The paper examines on-chain data from Polygon and finds that MEV searchers use predictable nonce patterns to achieve fast response times in auctions. These patterns create linear relationships between different signatures from the same key. Passive attackers can then set up a system of linear equations and solve for the private key using elementary algebra. This issue can affect multiple wallets if the same flawed implementation is used across them, showing how speed requirements in blockchain systems can undermine cryptographic security.","feed_headline":"Nonce collisions let attackers recover MEV searcher keys on Polygon","feed_subtitle":"On-chain signatures show linear nonce relationships that basic algebra solves to expose private keys.","key_machinery":"Linear system derived from multiple ECDSA signatures with related nonces, solved via elementary algebra to recover the private key.","core_discovery":"Searchers employ predictable nonce patterns that create linear relationships between signatures, allowing passive attackers to recover private keys using elementary algebra. We provide a compact linear-system formulation for such attacks, including the dangerous case of cross-wallet nonce collisions, and present concrete evidence of exploitable patterns on Polygon.","pith_inferences":["Similar predictability problems may appear in other high-frequency trading or auction systems on blockchains.","Enforcing cryptographically secure random nonces remains necessary even when response time is critical.","Routine scans of on-chain signatures across chains could detect comparable reuse patterns before exploitation."],"forward_implications":["Multiple signatures with linearly related nonces suffice to recover the private key.","Cross-wallet nonce collisions enable simultaneous compromise of several accounts from one implementation error.","Latency pressures in sealed-bid MEV auctions drive the adoption of these insecure nonce patterns.","On-chain data provides direct evidence of exploitable patterns in production Polygon activity."],"fun_headline_variants":["Nonce collisions expose Polygon MEV searcher keys","ECDSA nonce patterns allow private key recovery on Polygon","Linear nonce relations crack MEV keys via algebra","Predictable nonces compromise Polygon MEV security"],"cache_read_input_tokens":64,"weakest_assumption_plain":"The nonce patterns observed in the data are systematic and persistent enough that attackers can collect enough signatures to solve the linear system for the private key.","fun_headline_variants_meta":{"raw":{"variants":["Nonce collisions expose Polygon MEV searcher keys","ECDSA nonce patterns allow private key recovery on Polygon","Linear nonce relations crack MEV keys via algebra","Predictable nonces compromise Polygon MEV security"]},"model":"grok-4.3","cost_usd":0.006869,"raw_usage":{"total_tokens":3053,"prompt_tokens":557,"num_sources_used":0,"completion_tokens":57,"cost_in_usd_ticks":68690500,"prompt_tokens_details":{"text_tokens":557,"audio_tokens":0,"image_tokens":0,"cached_tokens":64},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":2439,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":557,"tokens_out":57,"duration_ms":31609,"temperature":1.0,"reasoning_tokens":2439,"cache_read_input_tokens":64,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-05-22T00:57:15.606643+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"Collecting additional on-chain signatures from the same Polygon MEV searcher and verifying whether solving the linear system consistently recovers a private key that matches the observed public key.","supporting_citations":[],"review_version":1}