diff --git a/src/modules/frost/keygen_impl.h b/src/modules/frost/keygen_impl.h index 65954dd1..f83a8ebc 100644 --- a/src/modules/frost/keygen_impl.h +++ b/src/modules/frost/keygen_impl.h @@ -293,6 +293,14 @@ int secp256k1_frost_trusted_dealer_keygen(const secp256k1_context *ctx, unsigned ret = 1; cleanup: + if (!ret) { + /* The loop above may have written real secret shares for the first + * few participants before failing. Zero the outputs again so that a + * failed call leaves nothing usable behind, as promised above. */ + secp256k1_memzero_explicit(secshares32, n_participants * 32); + memset(thresh_pk, 0, sizeof(*thresh_pk)); + memset(pubshares, 0, n_participants * sizeof(*pubshares)); + } secp256k1_scalar_clear(&secret); secp256k1_scalar_clear(&share); secp256k1_scalar_clear(&x);