NRDAX-T0100 - Handshake Crypto CPU Burn
Compute amplification · P2P and gossip · late bound · active · first seen 2023-01-01
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
Neodyme ND-FD1-MD-02: QUIC INITIAL flood → per-handshake x25519 + ed25519 sign-tile CPU exhaustion (compute-bound, distinct from the connection-slot flood)
live exposure
No exposure data. Slashr ↗ has no risk signal mapped to this technique yet — absence of data is not absence of exposure.
instances (9)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| bnb-smart-chain | bsc_rlpx_auth_flood | lab | NullRabbit Labs | bsc_rlpx_auth_flood | - |
| celestia | celestia_libp2p_noise_preauth_flood | lab | NullRabbit Labs | celestia_libp2p_noise_preauth_flood | - |
| ethereum-consensus-layer | ethcl_libp2p_noise_preauth_flood | lab | NullRabbit Labs | ethcl_libp2p_noise_preauth_flood | - |
| filecoin | fil_libp2p_noise_preauth_flood | lab | NullRabbit Labs | fil_libp2p_noise_preauth_flood | - |
| optimism | op_libp2p_noise_preauth_flood | lab | NullRabbit Labs | op_libp2p_noise_preauth_flood | - |
| polkadot-substrate | substrate_litep2p_noise_preauth_flood | lab | NullRabbit Labs | substrate_litep2p_noise_preauth_flood | - |
| polygon-pos | bor_rlpx_auth_flood | lab | NullRabbit Labs | bor_rlpx_auth_flood | - |
| solana | sol_tpu_quic_initial_cpu | lab | reverse-engineered-cve | sol_tpu_quic_initial_cpu | neodyme.io ↗ |
| sonic-fantom | sonic_rlpx_auth_flood | lab | NullRabbit Labs | sonic_rlpx_auth_flood | - |
references
cve: CVE-2023-39533
cve: CVE-2025-29606
related (Compute amplification)
NRDAX-T0006 - Async Runtime Blocking VM Execution active NRDAX-T0076 - Expensive Debug RPC Compute Amplification active NRDAX-T0088 - GetData Request Flood active NRDAX-T0139 - Legacy Sighash Quadratic CPU Blowup active NRDAX-T0143 - Malformed Field Gossip Before Validation active NRDAX-T0148 - Malformed KZG Proof Mismatch DoS active NRDAX-T0166 - Move Verifier Fixpoint CPU Exhaustion active NRDAX-T0184 - Orphan Tx Resolution CPU Amplification active
cite
https://nrdax.com/techniques/NRDAX-T0100
plain
NRDAX Registry. Technique NRDAX-T0100.
bibtex
@misc{nrdax_NRDAX_T0100,
title = {Handshake Crypto CPU Burn (NRDAX-T0100)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0100},
} json (csl)
{
"id": "nrdax-NRDAX-T0100",
"type": "dataset",
"title": "Handshake Crypto CPU Burn (NRDAX-T0100)",
"URL": "https://nrdax.com/techniques/NRDAX-T0100",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0100-handshake-crypto-cpu-burn)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0100 nrdax cite NRDAX-T0100 --format bibtex