Altcha Proof-of-Work Obfuscation Mode Cryptanalytic Break Vulnerability

Vulnerability

A cryptanalytic vulnerability has been identified in Altcha's Proof-of-Work obfuscation mode, affecting version 0.8.0 and later. This vulnerability allows remote users to recover the Proof-of-Work nonce in constant time through mathematical deduction. The issue arises from the improper use of symmetric encryption, which exposes secret information in a non-confidential manner, creating a total break in the obfuscation scheme.

Impact

Exploitation of this vulnerability allows for the constant-time decryption of obfuscated data, including the recovery of the nonce and the original plaintext, such as email addresses or other personal information.

Reproduction

The vulnerability can be reproduced by using the official Altcha obfuscation script to encrypt data, such as an email address. The encrypted data can then be decrypted using a custom script that exploits the cryptographic flaw, recovering the original information in constant time.

Added: Dec 8, 2025, 7:36 PM
Updated: Dec 8, 2025, 7:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.