Easy DSA — GPN CTF 2026

A P-521 ECDSA oracle derives its nonce from an MD5-based uuid3, so an MD5 collision forces nonce reuse, leaks the private key, and lets us forge a signature for the flag.

June 5, 2026 · 3 min · 594 words · Th3B0yWh0L1v3d