{"_id":"@polkadot/x-noble-secp256k1","_rev":"47-64b76d9cc74116fa7c53d80ed915969f","name":"@polkadot/x-noble-secp256k1","dist-tags":{"latest":"8.1.2","beta":"8.1.3-28"},"versions":{"8.0.6-13":{"name":"@polkadot/x-noble-secp256k1","version":"8.0.6-13","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.0.6-13","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"09ac01b87d4aad38fb2d5f9c0220e3ed11d8dcd1","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.0.6-13.tgz","fileCount":9,"integrity":"sha512-TFv6bbZWXsOnm+lNTcrieuQlOFnoBIECwUc3DPEkN3dqY0LQhVTrrI+IhbgVnCad6+CpfExeppVmLML2UjMSAA==","signatures":[{"sig":"MEYCIQCFDDpEKbp2KbXKEE/HIiSpZYXJNgA2nzJ2ss3UV7/vtgIhAPU0fC8CJyU3gLpNky6ae+vdkjcb8e1vjiGDzl9TBDbc","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":100129,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhqiAnCRA9TVsSAnZWagAAh8IP/jIqpge/86/3g1X1UK5P\neMNc27UPIW9RReZ6NWXUPxeVOaWdk4A1w/QQcx/XfXQhk9RP5RKseEBjr1xX\nFHKimM4p9GR4oPepoNrwfjdI0/whokCNRvdsVJFa+SzyYpweG1fGxpBFxdwC\nmqPJIm1u3mSswbR8wEJhISolvmLs6ypFlQUUmJs2EAD2ouJZDgitB2S08Avk\nHGM4ahmsrmVb2HkKoZHGn3tcD2axEnTRfDaU0oCdLNVrwfPLr6J7MfTb1a3/\nCBpXNratzfd3hfQSPdZ/SKSV+jdFlhX3AukmDxNQUEEM44xkSJlXYy6vBY3Z\nfFXuL3GgihGELLYzvOWSRxdsrLCeosz/CDpstAz2jmQg4nr7VCCxFP+ewR3g\n3f/zerhnrDK3uuVJK7gURwW+zi8QvckK3AVsy8zs0XiMuLnIC+QzGlEdtoed\nAejRtqrc/STTkPDxPtcT+t5zRXx90RQBPsxiawMBIxaEri1ZkY0iYwPSMSPP\niZkiIq2lqozIwKxp9Dk0B+KP4IekjLyxChK/QW4MgcSA7xiht5YSsQQv0YJM\nZMMsGbCF7yBcxo4dvC7NoETi2j39fm8mMX5JJ18y8wp2FG2wGaL4z1Pv/5aS\nrW8gaAkja3uf8v5bMcA+yPczDkdwoYCC12gr0nC5X3ETZZWL0Mv5Omc6AcQ6\n30cQ\r\n=xMTw\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"7bfca0d40ff7fdeb38ff36b3bf9072eb6a5084ec","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3","@polkadot/x-bigint":"8.0.6-13"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.0.6-13_1638539303177_0.3157237139776159","host":"s3://npm-registry-packages"}},"8.0.6-14":{"name":"@polkadot/x-noble-secp256k1","version":"8.0.6-14","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.0.6-14","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"5ff5a1e881292de790d12f384f6fa0d149986a36","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.0.6-14.tgz","fileCount":9,"integrity":"sha512-gMX87d+U+heugBUAdGgYrdxJd9EKSau/1T/cPGu2F9SGkG5uB0BG/+CeiTINTF7wO5enYNig/7vF3ZFo8hkujg==","signatures":[{"sig":"MEQCIGZhF+tG+AZO+LjsVwbS793O9MUR27mqlLLtDfN9n2ZmAiB9HTgEu8hUNMMzGcXvWkn684wxqF3CSeflomJJyHoHbA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":100129,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhqim8CRA9TVsSAnZWagAATo8P/3V2//Mktbmp3ih+huFZ\nKUCugU4IvypNylKfxuFfyBciqpStVXG4S3k1cbGLqkduU5f6dTNm2GNAh5FO\nfx13baAxoteLgzZ9Vd9Tzgg49JiNtYNGSqxD2vbgCA1hWlsEBXZYFzzXk1xL\nyWN+AhIBJUSpJYkAc99yV7R6822jCxq6F++aTN+VBz0NQ0Uy/uMWg6LOOsNk\nQWdF0vQyQzGaUbqYepRkFmsNefGcv9NN6EbHan6Bt9xrMcdvzL9lln4AZ0Bc\nbHxG2UWshkTZaXXVvFp7/gNApBtBsu+210csVGZBf6eeK9KLIdbVJTBNl9AX\nIez5QYgFUBEA4fSA7gTY3Vs528E31ptCw9A9NplzW7O5fcR94+KaLtCk6OEO\n3ikv7SYXcMG8s9Jh3UppTkwmoblqJj2uKY4Xy/MRJX2d4Yob1GEfyiAyB0Ti\nfF+ljJRLbK2/9PNI7X/9IwBOLik9xiEjy5Q9iv8IluZfw7CfyIMc1OqZ5Y8/\ngfJvcTDNYnXwF0IXzpotS6q9IDWGYT9hHzpkiode3iATlZsRKVrDoiCkcm+y\nFuAWGuorAfwW6Ci01+brBIcBx9iaXrLrw2HFgFlzeQU5cpelWScJq658dFj7\nbNfcJIEth1cK7XplX+ipSCftVtRK/og2ghhjOZlb0u+SBSDWVBSNyGimbcBQ\nFewF\r\n=ARCY\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"88c2d1695197690f3ae6f552a49761d50f13dd4e","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3","@polkadot/x-bigint":"8.0.6-14"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.0.6-14_1638541755967_0.6084030350651244","host":"s3://npm-registry-packages"}},"8.0.6-15":{"name":"@polkadot/x-noble-secp256k1","version":"8.0.6-15","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.0.6-15","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"5e2f2e1155376e83359e0ec14b88e5cfde9fcf24","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.0.6-15.tgz","fileCount":9,"integrity":"sha512-hen3a6LJN2YDjF0+x/g5Glp+wOccHv0/qz9AIt58b8zRqc/N/jRaM/C392wlS6xPUTi4FEy5h9VzGI0TNjGBPA==","signatures":[{"sig":"MEUCIE/lfsIUHMsEZjC8WHutb/ADmZQnFmWTCnsix/+mSVaPAiEAhog/rIjaoSznTxGzulnGSqSaurGtT6d/qqM5VmTdEII=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":100129,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhqjgACRA9TVsSAnZWagAAM6cP/RGt9j+X5m9FI5Uek3a2\nfMVhgESwWpiXWsegxW2+cHdfXnof+JGaNzjbxWD4aSlTc1PyFkYxCtLUt2ur\ndh2eDL5Nux6hHUEYDOXuMR/nrOAdh1/4ONzknzypFPyQj2HN6eJfsWNDFWTK\na7dfsgZpGSB4/xasounNrduOEGdmnuedqon/7g44ti3QJd2NPtaKysDicQy1\nd9QV7uTBp0A+qOFSUxT9BQmQpXQWth5NSWtUkNgjwSnyn6iRd824mPPBcU1X\n8VCn4NzEvNKYSBSwBgT/BZ9SV2a39G/HvVzd1fnwW4QM7Zc1QDwO4Kmqsvk/\nJTzcbegm96FIOmv7zzQF+2agOIRIkgTIytHdVaUFlhq/TL1uoW6ppds8opFO\nJ2Sxkn1xE6HGdrAsApygjUaJqThTJx/aXw9M5wgZBSTzk72vtl/xpR9HzSpF\nOzo6/oDcuPYPchjEPF7sMSb/+fyN4tXQmeWX2VVvzRAV+mYDzOE3SuNKAR8G\ndlYc7nrbRKiDwP1C4rG5VqQu0Ql/Yg5ENCMXru8qY/SBiYaT3FTvfdG35+nJ\nQej4oopdqFuphCQjbqyxgtywLyBb6ugbi4I4AfW2C0N9zbFhFvnl1HdvJ8kQ\naT69TZF5NWvGzHv5xvKCx8iBws6wEKbwyWGuD0sn4XIU0XagRbLUae2c16FY\nBizv\r\n=cs95\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"986dfe500698270f653a3b082023c37d69b44cf5","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3","@polkadot/x-bigint":"8.0.6-15"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.0.6-15_1638545408478_0.2725023998188296","host":"s3://npm-registry-packages"}},"8.0.6-16":{"name":"@polkadot/x-noble-secp256k1","version":"8.0.6-16","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.0.6-16","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"251013ff7c4875d4f4994c0e51463c567fb56da3","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.0.6-16.tgz","fileCount":9,"integrity":"sha512-O5PbgYc+pHfjInXuJalzu8btnrGzdsMEnIAf44t4LF6As/TzrDXsQpbXIvusT2ydtRhy+r7GaSGPYPVuGUZ2Cw==","signatures":[{"sig":"MEYCIQDg/xmwKNP8WJULcQLLXNT2Vh+CWNz0apd5GumOPJs35gIhAJdFMUOCfgsMsCnrntw1UW5wvesqGo1rEKFFQ1r7DBpQ","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":100129,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhqxX7CRA9TVsSAnZWagAApZIP/3IQe3ludkfK0WkJq8pU\n1P8yJliUpxClfnD7mQ4vXMtUt0sEMsKqmD1fn8gSusMq09xsjEv3gcyHDypd\nvs1B+5zSQWx7f/l9YHRhV0fkBjV1/+ZCt+pb/ZvQt/SZlwWFSZKRGXqY3jq4\nnoowPBbKjuwppg2FgelGTRy1QjfNMIjoic4mzaySn+6C10mO2QFoDP1v5YfX\n58dfjVK2dakJYk3enH+64+nyHKJKxbaBnrBomwUbWEKPoTf9nX/ai8mXcAvV\n9r8ub8vZAqn/L4AsvDVUwMkfH0DfAgZ1Fco/m7sgox34fdHSJ5K5nU+ln3gP\no4YPz64AdemDbaD4C9f34payHe8dWgQ2z3Xu3bBCcFXJSPMIfUhFgpvgr28R\n7YHO1O3dwyz+61eZqRkJA0NFM/2zIrLsSAnN5GxrXbw7pZMIPCLSsP8u8vcC\nZRGZnTVcgBswPQsgCHPBmadrJOafTjvY7voBpzlN38oLQDJGX3yCrEaEkLqm\nhzvKJ3HACrrK+hA46miS7E1fnufc593GSfT5VL2s2h8cnaCgBkyAvLP3L8MD\ngN02tbeoepElfdlvwHBGkTVu2Q5NbPdjfUXkYQttIk4oz9Fo1FX0pthEbNx9\ndXIyfcmXzHw/TGZYivk3v/vCLbhxyE/dBE//0uVvXiFOd+MAVoqvrKNAHsa3\nIyCC\r\n=arSE\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"ee7923c45787fdceb4bade9a6d50ea162fff0ad2","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3","@polkadot/x-bigint":"8.0.6-16"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.0.6-16_1638602235164_0.4131899216941539","host":"s3://npm-registry-packages"}},"8.0.6-17":{"name":"@polkadot/x-noble-secp256k1","version":"8.0.6-17","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.0.6-17","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"0eb2b09e2bb36974684cc7e581a90a620e51b488","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.0.6-17.tgz","fileCount":9,"integrity":"sha512-4C5ZSjZxoiXub5MxVghVCoS1BYqakGzxKSdfec84/1FcoQpJHgg0MdTnMKyGRlcPgHngL8kMMEqXjPMY7KYIPA==","signatures":[{"sig":"MEUCIQCgVUup/BN5tbwNQuG3eNCzXtlXAB65BlZj0Hc1C+X8BQIgBEaoYsCoO2lIwI35dd3K1ygSCG5JdWy/aLx1euGc5NE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103520,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhq0roCRA9TVsSAnZWagAADLUP/051i9UbCYcf74oLYkNM\nPAVenYvcdme3cWgdb0j9XnwOqn/eGNXSpclkSaYH0s+7eAsBtJ3cuds/azba\nJmnNk94WE1eBdgCIx/Ut4OQebHPIdTfl+g2lp5KFdAUr/Qz5xcXanHl3mz5D\nmlAzdBlxndqa8HNSHuDsVGUB9oUs/YjrPZAGriWOMiCANzTIiJ3Y09cSuJ95\nIm0m7Kh2LfOZAR9spAljIErDCIMwAKIJgB78f7YKOMoYIQ/HIqUt7gNatFWb\n4v2btvXzTcGtUf05XEniQhZpMF86Hc88SDwTatCutu7kNkAL0XKR+/e5alWX\nTG1pUY0ffVB2/xAOXFHqBS2gB3X87eF01E5FU+HWaZLtqwl4f+yD/lsvrmE8\nOSu4KCmbhL11EJst/5nujoqfj+ZiebIMSa3NqvpzJIzo54Lq7RVes1UgQcwB\nXtckSd7pNLNLA9ItwHHNUc4s5daAqvUN0710IgWfbWa9cPZMBeaShcy8zGgD\niSaI6J+rrLej+z5ygoHWbxJTArdbYgkBMDnh506bdqlX6SvUZQz6oREoREEx\neej1EkPDvGQlGt8czqa88Qx6iaaxMm2B30LW95RBYVeHOxqy6+eV+X6h+nb8\nrEOyn6A+3KpmIdnIvI/gDMlnVRnPzz70Mbnys0GLHgnQDVi7WNKJhDH9XfQF\nudmN\r\n=gfTv\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"699ef952c37c60ca3fc239fbee093f96e6ef9a1c","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3","@polkadot/x-bigint":"8.0.6-17"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.0.6-17_1638615784691_0.5992925862386413","host":"s3://npm-registry-packages"}},"8.0.6-18":{"name":"@polkadot/x-noble-secp256k1","version":"8.0.6-18","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.0.6-18","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"83edc17642d2fd88fb0f94f32edad17d099099dd","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.0.6-18.tgz","fileCount":9,"integrity":"sha512-jxmg7ffVWlaRcCgxb3ZsmpGeRKSecIa1pDu9Bt1lnpdoPX+xkE4q4wKMyeFmPBL6UvpQDzZWldxij4ev1JvT5A==","signatures":[{"sig":"MEUCIHAw8TP/nwEJtnqwW9FU+JK2/unl5J/dV+gd4ASwvuJvAiEA2SlmNtrvv5MKkTvNp5RTMDfpzflqsiEXofKDllDk2l0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrHVACRA9TVsSAnZWagAALf0P/0h2PmyM73VMQGwEy0bs\n4DQ48THAuw7On9Sf/CRel2axuNTVhkSoGmjt5dOAfbpCFQ8nGF2bk3ZPYuaM\n/UXMCdmH07omAb6k3pxMUbKlZEymbWiGrVusVZrcbHfWHunjpUy/jh62rcKi\nXF1lfoZQfjvT4qb9TsY6JDdaa6GR7aRxwzyua7UEMUrV4AMEn7lL3++mEAzU\nze17+Hu6azvh3mctcel090fWwi74REE/YvpTUD5OTZyCdCFA2kz1w9jeDzQt\n4+2RzudsTUr2A50OcQp0wiOqp5HaavF2kfRr0nmd3gQ3hcB5p4NkpmMlZXkY\njUPELAZQCTiOKHLD24eaPUirqnc/WGFsYX+87jRFNCE6H03ruEe1sm8O9KSX\n11CQPrSxoMKI7DtDk4FbnlnmAgvFzTwAu+1HzJryagxHlgGdbc2l8Riion0l\n3BNU3IZaoMI1ezJhoOtV1cTMKudGUNf2TeSVzUeDYpD/AnXim+LAsWPHAFsI\nkV+nqutJyL6zi0PP9S+pRizMFeo8x7krYC6mAlVhKwkpmRMp3KbBHBy70ZPO\nOJcjIWyLB+44vM6bMLtrvtxtd2H81UrCyiLWQXWZuaT8Npm0axqg2SmH68fz\nfGzajA/TYg0t4CD/XUFl4bXVVAalgQx8AQHXMWiWgO0mya1fYHVfiC2wy7uB\nr68+\r\n=3gfI\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"e6777ece622346989d4370a7b8f6dbd1078c9e7b","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.0.6-18_1638692160851_0.6594497618375506","host":"s3://npm-registry-packages"}},"8.1.1":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.1","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.1","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"63eb21c6489b45ed7889485c1a98b87324415760","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.1.tgz","fileCount":9,"integrity":"sha512-7br0aiiSygl5szC0o1NxSTdDV11xjXotho7Zyn8q5sGHJLJh19sRFeZruRQnji1Asj/lqnSyzexeFs2MtIry/g==","signatures":[{"sig":"MEUCIQDzW9bJr+HovbHibVK5bBhcwpt7aJZwzxj2GUPL+tOsfQIgKp91CKPwlsnxDP/5RfM298pAni77i8QunW86m62Q+wA=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103473,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrH9vCRA9TVsSAnZWagAA/w0P/jt8MAEglcF1zSID/102\nCdYqdOSbWJsaP4qzdh5LghZFz11eIjSy/p1cbus+2gD7RLY/KFqcW9GIZZ1A\nsqo/kqGl9YkyVMBUjOle01N1FN/QkJFNzSlEvn110q4ZcQ67hscgJE07drGF\nFhNjHAcQ0HAykKv9DWrWs9xB+VUYLx+zTOEYFVdfuFz66Ybxjf3sPsVBkjFa\n5rry4Vz5S1+SCYk3lGxzfHp3y1jRqJsiXiRb9kw6gyKvEx6KWj3F8uH8b4IZ\njD0KmqU2zvVO+pLUJ25XrLGQnNrvKugA+G0+B28osx5e8mkClo7NzLiZ8/pE\nwvlFqh7A95YoZ2TzAUNHd2afaScjtwzPQIwchPtumrzVIQu1z5Je+K5yluiQ\nXduYXzs5MTkmuVisd7Z26j3UQD+f8C8Y6lC/oqYW/5A7ZIXChN5+BJ9olQE5\nmPSDfpGi5fsWmXBwe1pYSbydR6tAVIf+AwOnDer9CDnJ/qsOaJsA27gZaDkV\nJlxoe0xBjSflFwJuq1VECxpF4d55tvuieRz4FdWHsTVz6pdhKMelwmAkToec\nPKOpZcEJ2VWnqHWGJxr84igvPe1kF0PFfnBr1Ns6S8Sf7zmq1Z5nMmNVtox1\nak+yzMDe/SW0zoEU4k9rwzf3PbTRbVBmUbWozmomKOSEz/a5d5GZI/XNhymt\nqkeO\r\n=6bsj\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"05c82721e8f76f1f06e2fd0dc725120b865ab8e3","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.1_1638694767215_0.6242634844079462","host":"s3://npm-registry-packages"}},"8.1.2":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.2","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.2","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"1e29fbb01f2f01df62fccdfb4156f0d046a37799","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.2.tgz","fileCount":9,"integrity":"sha512-6fSXJDmEHxWmNQ55tnZTx6xbH1sFgCjJLxyIwLcqJuH9rgaNALloWbGvcG8C3NVbqh3REQRSC20vfabqVjrCpQ==","signatures":[{"sig":"MEUCIQCynjYujMdiyZd54YS6tgCyIBLIsRDS5cWDnKr/UlSzJQIgCHm3c7NsRDyLJoH0XKw+y4eRJkmWFRXD7g2UOhHiAg8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103473,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrKCzCRA9TVsSAnZWagAAlzIP/12obgUhkAbX3mkgxlGd\nSR4EybuLgClUnmurntgXz3jjmSfo+r+9lr0XpWjn7xbWot9SqBl7Ng34QknJ\nwbItwFMC8XHUx9/mO1r4yPd08Ji8lMOWGq0GpO/Glfo+1UuIrVcxk0XtePEU\nGDuSruJxkwNlzrmcZeIWDrgZZ2xr2gm34j/ygpmMTfdQIyRANHb1NsF4kqNr\npIYYrtIvX6xHsRjFf1Ljzlo6gwY9cAs4/foX/AJasYt6eczVB+cFQgtjuw6i\nhib2K4z2VmDUWZKzRuDpJtXU8Cq+uTtZrfJo//zPSyAka1K6ELO6y3TIoIPR\n76x0LggmVpjGp1Xb2RAivkyeKUYp4kDR3YffsyzP9n4hoImZfCbw26/p6VnN\nte9ciINfkb/r449moidXZKlEppMweyvRK8NPNv0zu9boa0OgkdGXU8/aDATk\nJT29nHJb7jwIlBvc/hv9FBp42Dwz9r/5D3NTJ5in/uTqIRs2Fv381Y0dovon\n/ZYrgm71CVjd/yQOdFk/x80gzp5SphLoTyemtAqu+ClEkz60AnUmT4JuA0He\nPJ7LAfD3NuQEXxXaBTh23NI90Y/e8n6zimmB/Sm+DLknXebvvBE4eY/Kclj8\nxBqFXhhCYS3ceQJJd5v2E00cVfymSFCS0GxPSV25Yj1FjCk9r+d+vwHMkC4p\nzP0M\r\n=aTst\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"80785babb48f5ce2c5b686996c4616a41ad7e176","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.2_1638703282890_0.19666184742345694","host":"s3://npm-registry-packages"}},"8.1.3-0":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-0","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-0","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"d34adb0368f64d33ec131c1be77672ae4ac6eb0c","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-0.tgz","fileCount":9,"integrity":"sha512-OBf8Nmj4iwePNnUs0tLHcRYnwc5+N9uQWfPVZSmj12MPxyn9RrHf0GFcu1r4A6ZxEIX8zOKW9TM4m6XiWMsmPA==","signatures":[{"sig":"MEYCIQCokb+A3TiQRhZQQeH+FG90kj+NHDwdW+/Wb047YF1lBwIhAP69tW4bIXPQrm/qVT9GqRTtqIbasEUrpM3lmQmMhiC6","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrZs9CRA9TVsSAnZWagAA8KQQAKFn0BIkSs5CMzX8Jigo\n88djVpK2qqgst70FRGIqiCXCG/Oee3hnEAb6gxPQYCisySwVGoxLL1dvthLE\nVV/8M3s1L22X7cPX3aeD0oWqgPhx98Zxx2pR+Sxr9nDNtn76K1+7K4F7LeWc\nLQX3zcHNDOYA6VgeoJBxD23wk0QtUtYBGGHyBlM59Vr26vuscIDuY5M9Wvbs\nL1JxfhL6fsDtwkmfck1VcPa0KKGrZofwzKbNCL8ldP0HZr2hgx1ozXMUyY57\nkYNt45HLtjmv6XzX9LZrKJ6g3dPxatIsLX6tlXr8ojyYGYZ0iSd3Ly0CoEvr\na7LugLXlpMXbK000ScvdTto2GWhejGCNFussdv1AHFqxP6m0g492QQQDblLB\n+GrDrTXnDjzu4D4BXPho87tXLGR9sLJbf7Y5+v82PJ35Ja56T2Q9sof3otbp\nSiUFKg6+B83JSgxWQEZeE9ICD7NrIzgkxqYCHIqRhcLXo/vmetnXJ/GXLe5G\nOaJjzxv6hgF7KbxdsNeZTtBOHauYHsfwOdEJ9Q4jMOXwfdZuPZbyWVYn2TNn\nARo+foQy+sRGXmd8w6HFkX0xF83TB4FKqxoG2v/R/OyU4huaqhJXorXb2UzS\nROddFQjNLiJEWiys3ImJNfibFNi6cgDrmsnxj7bRFAIFqvhUvWlXALIaE4Uo\nNZ7l\r\n=KrvK\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"faa6734329f7cec9ba4aba124ed154ea087f4bc6","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-0_1638767421239_0.2270802788900823","host":"s3://npm-registry-packages"}},"8.1.3-1":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-1","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-1","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"8a9083568ba22c47c55d359cb30a82617176fd1b","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-1.tgz","fileCount":9,"integrity":"sha512-Z85n1832qRuqfO9ja+AU5yhZZ86HlxSTAfhhn/ZFZnL5QSOjPmFzCIuyBGlsEhAsbdTglNcBFLqr+Qp6+nw7Ow==","signatures":[{"sig":"MEQCIGOE64wItKpmg8kv5xLk9YsHOC0Z/yN28Nwz+RMUJvAhAiAD72BH67YRZh7W+an/RI4j9x2N0vnWckC9+rYbNC7Hlg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrbaSCRA9TVsSAnZWagAAAW4P/08vUh/cKnI24zWinGLM\n1d9SW6ldDn4vHqGVpuqce4dmUiz3RAa40TekA9HXurqlGVF1Z6RhIe+mCjKc\nixskf67vrQzc2xweRkipNa3OoeFtGka02DEP7B0Rdm8uA8MXPV++5bS/JXSl\nnAqogLleLBhu7FhT4mhMC9Ch6ciOsbXZ7h3KJxi96f7CL5/uVN6YCK84IxJI\nesImKvGRie/BBu0ern82gRDr/tFxqEKvBmPlXGrR0mdIt4NuOrw4vNf5Mnb4\n9MFdmecKRYm4fLNccyla2tL8OjT/tIT3pemf+ilO7vpwI/EjBtsViW8sW9+U\nS02nfRaKc6yUGqNQtM25lhf5EnWldTSAzK0pUEKbvpxkqG0uDC8NL2C2vi3m\nlWgKmqVjTkR5PpEZjxNDE+tgvNN/egP1izv20BUhgGQJCrlrWVTf+6opgijv\n080BSLYXPD7NUrRbju7cDt726Gi9fvrfWIaJpC3V0cSlh++ejIdWQ34Th6ws\nARSvrWEZEOOjK7Quuaa74Ej0VCkEHyE5gXkl1pxaQ1A6gAXGz8cc7249KsPU\n3ga19XJoXMxYW7gG+Xk9zhK55p5o6Fv0VCA335ISYCgYAIFTyprNVQfMxUmj\n1v5xkfQW8l5EjkX8hZjed1YnFMS70baRClYxI2cD0HG+C8oiXrWhH2IhwPNa\n61s2\r\n=qIhc\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"0908dbb8613e47dda447e965f1c8cfb669f77706","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-1_1638774418451_0.7458599845546683","host":"s3://npm-registry-packages"}},"8.1.3-2":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-2","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-2","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"79b3e6f79dfb46df1f2d532f75ae530386ece96d","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-2.tgz","fileCount":9,"integrity":"sha512-gbqbI7d/74GsQDAIfANNsRUKjjAVvqEWmSmLCy2DAi+D923XkkUTMpm7RI3uJpgocooX1rH/Hj5LKa9rom3njQ==","signatures":[{"sig":"MEUCIH8YyDV6xCEf5r5wwcQkZS9tlqLL/F4w9pG4j+xsTrpJAiEAzx8HE1l0bYMggFw5DrVB4Pidkp3w9XUXicuRRzMsW8Y=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrcnXCRA9TVsSAnZWagAAO4YP/izcFr0xfvWhd/HPNXTn\nJta9fKuO6RhWpkqJZ4N5ScWDPATvlnmCJykm2PBdDxfa6HVA4jgsChBTETdl\n5/f+30DW6pelL7MfOYjPPYF/AG7yhWwJdVj302RAMuEwQZs65x+uONI7HA80\nwxIZIq7yZiwNbNubgu+KMTqIAoBb7TjjBDPrtKSG13VchG5EhNUttmyzl3wu\nGw8CcKC/JD9xgKcOzvuzLDyds4AgKPs152l0zX5heXDSyzPPNplRdhPmULXP\nS6ckwg8c9o7outijPmnV0IX78gjML3JlenboovoRfPdohFUQpJqzd1Y7oNJK\nxMIfXgQXTW3lc6onQBhOdd406+DOdc5lHLbqilk0z23nSYSykQYmr6B8GNvR\nQfh+e7FmcxZGsiuEiT+ot2pRjdcFsVXJVLc5nb6ucc6gYXlF6JitkxZxpMMC\ngtFJmmdTcjvOjBvUOsVwd2g1666w3ZgooV2ZbKB8N7jJzL4cWzLLkFMf2MxV\nlX3N9bIu+oLIeReRSqsR6ETw0LLTMNOrmNtkd9XI73ogas3dARlDaaKa5tzg\njUR0rEzP2fN88TAtkC6fZc0InGP/kFFUvRo2fEIJXkQFTEfLfiZBpkcpSvTI\nk76TMRb+C9um1M/LGCAcERjHFbBv2hYbjMBlbkvxFhOPA6QuUDmR4YIfX03g\nrSQU\r\n=Bgn4\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"e52fe9a838b7e2e36e545ca483e74bbb9922fefc","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-2_1638779351223_0.975735734747228","host":"s3://npm-registry-packages"}},"8.1.3-3":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-3","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-3","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"c9842477f00de8aad7eade392a75933c124583e4","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-3.tgz","fileCount":9,"integrity":"sha512-sH+Mfdoj1SJc7xjzhFEBdwegcmSZHUQrqPGFMv3gv0dVZEyNmKkF0ITK/QyAcm/tsKev92PlWpO25ZDSpaquqg==","signatures":[{"sig":"MEYCIQDXwg0iH0Wl9DnvbSxZhXJx4+KV9mu8m9LHa/Ww+tSgSgIhANiqd/MqPoLXCv3GG82UnO0uawc5cK66AHO1MbS63uCU","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhrgY2CRA9TVsSAnZWagAA3mEP/3AHQr6nPyYVrq9pZ6b2\nRFUqOOI2lTSED/2RLl03Ac1A94DOlHovhoQUGr0Ne8ELzHz3u9hSaP60GrHh\nhg/OhfLgxxgk231CMh0DMlmMfmZMP7tV5fPI4wojyJes9Q6V3tSJ5pIsrhi8\neqpau/MoE2zocFaZxs5EJ7iHmM3rHcGi2F654SW/dK4eG37sKS2GwS26m1vK\nXwkpUR47RQAFBkTsbL2QizPAjIgMHMz1aecRPVqkkAPlP4zKxZFtTVkpxin3\n8lYMWzsyUl2rhXPwWYAE/x+7Cguhi4/NfICztOm9HRRtcQrp3i8Cj2OqHIyW\nPnGlFglkYQujU196CIVPVzR1shKbGZfdKfuFe4oYXpTwDQ0jffuYvz44DCyG\n7y4SZxHGnIvVtLTNAw00ByDkB3bZHG/OuknXLq0R2lR/UHrJpTFEkFIVcINN\nv4gcdn4ZuPnIrbIe+GPT22sUwN3QabUUPCZDgoMpNKm+eioB/LG3a2HqEDJr\nbWn7Ppo2rtcZXAhqv6Bx73wY/3DafIjvnoURxFYX+cC6rYY9V7HnLy67ctyA\nWVACByEoszef5qz6Mg3gHExFNOZWMStMGCv+9GLuG00TUXyzlxCE9Ywv8TRE\ne3CWDEin1Gse56+hkewNxFa2oxM9sTRTTaThv255vkdu1PE53X9m7gZtwRpN\nyMe/\r\n=Y7RE\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"b63607c4a0e084e66391b7cc41eb4863c73ff078","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-3_1638794806392_0.3318267336058389","host":"s3://npm-registry-packages"}},"8.1.3-4":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-4","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-4","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"8c13a5d176331d67fffef0d329d408b70d55a79c","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-4.tgz","fileCount":9,"integrity":"sha512-7F2Qv0DTusd0FXwGdj53v1V3B4PYdzVzDrO/hbNUNip0ezZ1xesKYQ+ju7HGuZwyyRli+eSPKYGD99DdWpTt6g==","signatures":[{"sig":"MEYCIQC3Y1KYpZU7L39ob46JS9oWcOWzHpRGhrXWcDK5G0x13gIhAIZK+in/NSqfNUOe2m+eWztypsXEkVZg9xR9MwFVlbm5","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhr4EdCRA9TVsSAnZWagAAPvAP/iURJbPpHg/sReISUc3E\nfl8kaDg5N0uBlGIZPZ4j6o+UPvVW/Nkxlyd/qdFG4iIC6i6olOLGOZ1vkwv+\nckiT7POwFqkz4TYIgrQw1xaO3cKBeEzr5JoV9gHZ+Knel7aOakxgazkWSsgQ\nlsmIojm6NZQHTUHSCkmXwO2lY8lJJvaanAMOGTMhYtcgn+mlOUPKf/AwUBAX\nSbOZmWvR+hFGOQp76sPwYy3T9/EY6XnGM9nFcwilZp0ZCXWvgDa1LjRosaX7\n0szxAl2BmaUeMDC/+FERwY2fW0o806vts/VQ6L6CtMgkBh7TgNamGi2p3gJZ\nMdAOegGLMkDa7h5YSSVoGWD5Uk+oXdZxrzbL5QcmfltAgoYjKfu1XNgEbRWm\nFbwqLfugjQP0IYzp9PeFGkPH7Z0S9iLjWC7WbuIGN1BSbmki1TPcpcyJrhl2\nM/9PAyNVTBwyw4Zjq+5WQ1WTzBN/SPOSDA+7Chgt+JxQUquoQoAFCNLFSVrR\ndzcMggXRgrWiteVJSrcBxRK7wycLIIWfMswRfwc1XXtkOzxZBHbqbZymrUCX\ntsO1tZgFcVZ0iXnAEn3iyi7IuMdLWNx/JJZ0xCuV+kkgCr142ghA6ZGgoSz3\nwbE2m64WrxXbP+0iladtGGIdHKSNp9rUS3oYCGnRNt+0wlG3l34Us3m1ddG9\nrpTl\r\n=ohyx\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"dce16d59e6a3b789837bba51f5ce1cdbadfa9e50","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-4_1638891805724_0.4987598008105214","host":"s3://npm-registry-packages"}},"8.1.3-5":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-5","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-5","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"1478ee27e06e04c063bd37fd76f7f0f98630bbd7","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-5.tgz","fileCount":9,"integrity":"sha512-9KScU7zZrC5KCvbfCjWoNinGCAXqcKtHDiiNRXQ2+XsQbV6YbbGQT21MbyZ//w1jwX7wjBlWbHU8QPwtPvsZ3g==","signatures":[{"sig":"MEYCIQDd1rSG+v6g+Jo/02n8Jxduy6G8DtJ2+kIMVuEOJ2o+XwIhAIryDr27wDAUELExXeI6VcFN6y8vyEZfiavbaF09z3QF","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhr4jXCRA9TVsSAnZWagAAGkkP/3vhS4/NbBdxbdlkQAR/\n24PYV33CDNl33rPW0sLKBkJOqj3TNhUnV0ytm/SzQYXOwmNHEv0aPCmN9LTF\nxgdvgfLz8gdTKytsP1xooyKlZeHCi9jOjnenISISQM2Ut34cgmoIRvxP4dTk\noMXAjhCITBvJWddHtPis3iuQxdbfPuHOdxfzqmHbV84y05ukvKOqIrIgkgGm\n93NVMyVr05R9IQ2K9iVVlU/bV8S3o8DUuj4Hj9EgHZsmdDV0dAwsRpQWfFaP\n8JzlOsnbbEH42TtiGDBrG9uaM9jNs/8tS9uxSIwVqudL091AkyFhPB6Vxpdu\neDPXdlzYu6HlM9hRtaUMkO8NJVaBU0YL6Ofs7p2QXPkQ4DfFmlZp+h9Isl5b\nNOU9ut9zK7Nj91PqCOymPdWwSSWcz0Q51dlCvbnbuT2vMO/S/B/hezZ8+OtL\n/PekZmgpVHXaX6iaE8CW5exi91tAiX2vtAcjA6bgx/KHgSRkB1RES5l5WeOW\nVX/Y9wEKgv8gU8ycXpmW9LIrJuTxpEtsu6ShX8nILvLCmw7lfwjGH6rnllqs\nSYo6TNFIcQJbacI9sL3cyNNGlAoHkKYlLN9K0rtE8C0DDb3RfExLZYF8FDrv\nOZFMNfWWx78ZUJDFrRn2MBwtywubkmItjomWvr8Zd17aMxtgoKxlj1Und2A+\n2OqH\r\n=1PvR\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"ddc6b83e966a219e3c77d41f5a9e30e273ee2c54","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-5_1638893782956_0.07847449020191144","host":"s3://npm-registry-packages"}},"8.1.3-6":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-6","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-6","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"cf0a8d64e444d12b8d541ae97be2f8f7271cdd06","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-6.tgz","fileCount":9,"integrity":"sha512-4Cl9C3pUC1qaflGmMD9q0zmnKk2hqR1OP0+D5tFRzHouEwX0h6NvDV2qvOflwUAPr1+9aV3hFvSLpG2IzpuaLw==","signatures":[{"sig":"MEQCIBPlW+P4XdwtWxmiZpxdBZ807sXl0i9adwZEkAyck+jTAiAzrI/QY1hpFs2u3NPrxRXO0/5/erU/GXpZXFnRlvbboQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhr58HCRA9TVsSAnZWagAASF4P/1HHDvloCy+XuudSThnR\nExVoUz2XEqMdajGtfV68HNzYoDECtbFNcaKmvtEeyD5kuPjUselcuydtQrCa\nnO2q4F6KkoFT8YW/R9RrsRQQvyoL0xrV7hktLifuZu1yMWntkVfXq3Ms2k4N\nIOrwwtLYw2CjW8i5zWfuA7IWG3SFIiImg+f/thlpTbAFn+3elUcLsk+uYWPr\nDuNSKLZ+8vAj/kIth+ACEW8LKTfhzJ5ZNZwzIVpDklq9wB8gZ6yZk4fpQE/9\nouxp5pg6qEbE3sQddyZ8TXVtUP1h1hlZNwI4KSe3aup8fv001O2ag6zRBpV3\nt49UgtLGdJbHF4SMO+Bi447uYUJYlvByNivJGBMqXYs20amAnPiYmVo8PVEQ\nsX6GhoSwu+JN2kw0nLlLVeInCAYGpYLb889eN3gYRAjS78LrBYj3GS1Ppj3H\nLl2tWHqD55vydKT+zKsQMFs0hC9HhKyCAgrNqx7m8692+dghL3imJIY9Di3j\nCmKNstyw+EaAhWjagUrxPUkp8sgXnfgb7ARWz6zEamu5doDOriy0bbttBJdf\nVW07GZCLGqo3lq+xQQERE/fvUMjYEFtQ6vU9jPFYbV96yEmdYllBqa3H2bQo\nvQY5W9qHlw+Zv1bB/LPEDXTxNKvqNQctl1ilAPj8wMQo6d9Sj9wyW1vLE7af\naSvR\r\n=K7nk\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"21c9e1aefddb9d119fdb0e7ef5a2fa8db9708542","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-6_1638899463173_0.47189595118424665","host":"s3://npm-registry-packages"}},"8.1.3-7":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-7","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-7","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"96dfeadb912f5133e1e615e8b11399bc81a3129f","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-7.tgz","fileCount":9,"integrity":"sha512-Cj7lzRDS2A07v+JBFiaFnrdKEregRwDalSrrQn5+auw1aP/MmaEKZFCT0JbMSOSIq8Iea9Veblxi7iCkeJDf5g==","signatures":[{"sig":"MEUCIE+gDSrZ+5CTqON/ZsD8ic6p/dxKbU+TDsFxyMdsxaliAiEAlm4fx5rJZ9xYIdO+YcR5+UoCb+KhKsrLbq8UFXSSWIE=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsG3MCRA9TVsSAnZWagAASioP/0T2EejLxr1lweCPe7jh\nccXC01x34gfUJ1A22Jx3KtiRFdBQB+UQV6ExEQWHKNVSsRHHPCuMDqTkbmCf\n7IEWNKykplGUCW8/FTAJTm4vWzaQ7YfXB/W6dhPPq6/qwp+wKQyJ/vouc1uE\n1hADKXe4dYj+SqgEDCvKxMUvCmLcDkdhl1GY082uhig/grFCLxR87TdFZqIJ\nkDWHxer2LfZgM/t5nY+lbC7mhImsLaAGWZUw626yh3HMWVH+YaxzdPF+ckMN\n/Rdzo1BYonmjZ+t4/dcrHSRgj1MjT5JYVULInqIkZMShh4KItNUyO5ba00N8\nVdPDLttJ9H4TOTGF/3W1mJCC7Qo51+fPsd0wvmeiaWnbdz/2ad45m7Pkh3c9\n0RSgDDymzSbwBGCgq6QWpK4U0GM2vh/LgwC1nzawiqxJnoTHXi2lB5oXZEXp\nDk9AKYL9E0EkNMkTJdXQrP7S8EcUVt1+TvZifhZd6GE/p9aWqVLx1nxHvPCt\ncSU7HLVfy9vLO2ASRNrnBi6/XvNI8safrsVIej6ko1BX5JRQ2cESmOiP++Rk\nf0QQb5sqYOzvBpPyRQwdIOXqc+hjiPCMOqOf594Copx18CR8eMLgmpTRuBhc\nnmZ4Y99tLZPwq6HByduk+Y1xMjByxHUnmwAwvE+r9EeZ12+1kPbHBQvWn2u0\ncLSH\r\n=gaZZ\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"1a6f81e2a77250493a616b885bdd614d09cbdff5","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-7_1638952396126_0.016027668517788474","host":"s3://npm-registry-packages"}},"8.1.3-8":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-8","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-8","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"71271edbeb56ebb37f5a87da67d67a16abf74f75","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-8.tgz","fileCount":9,"integrity":"sha512-egP8J06HK1RkQumFsh1Ox8e9uJiClRZWxiNu08kiWX7u+2wwc61h6kxJ0L/mis98n2omVtInmD4yzrH5pcZcKQ==","signatures":[{"sig":"MEUCIE+qzzUYegiCaPuxBTMWvCE3oKEb77EFzB4xtF0MR2syAiEA2kxErBGoH2AKYBduUJDb9w6QHnNdY8hdhFzask14v1w=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsHHHCRA9TVsSAnZWagAAFzQQAIEZ31TAVwe0drYg/D9Z\n6/v5r4HGJU4+oiJ1iYYvOf80LbW6vD6hFbfLDm1/f9nG+WctiwGX8/6Zljsq\nTkHuvz5Ns83tO9AIZ1RoPwzVTqeQAos3vud+E+OiyhhYr63Aodqq0rHriuP4\n8Zw8S9KQzvizI8M34mYQE5EGiohuMcnlX0dWZ+2qDZ6g8env2QlKP6TI6P+q\nsrLkAMO2gocNtDEJ/A01b1EktYs1h1Fl1be5wKkm93hCMCOxajM8yQYJHkdQ\nLoNXT+kwmTcIzW0mAMSlz0fhKyIzTWfJn9f2g9jfA2NjR61Ic7AwdzvCZ67y\npmeiGwQY2r/YjEdTvdN+ZxNOxaEosTqj8JkdNhkXHxHF5nJh0WRdvvSl7qWJ\nhosj+GiOiVumMuTop6ynUUZjowx8LL+G6QIgJ7mF+R1vXy2AUDCi3a/0Rlc9\njMz56RkWSNPzK3vTzXOhIh84mFwoYpf2hV6sIr52ghibJIYt2EVsO94ihrEJ\nyGESzsFnlG4iyAGec8Ouy8VxZj5o5Sp8BU7KJfd5444LKB8Wrj8alMmg8d/2\nKgzpovBlGqMddd9jqqn2qZrb424x3BGtYwf+wXtJnLlPZROu34RA4mFOwP9I\nwswN4eWIXOpo478iBQr6MEMMuB4Xl1crVByDNBR4RXc/qBt23BkQ15ZEWDqC\n5igG\r\n=MY6H\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"a5df4ed764df60047abc19ad69ebbebefc4bada1","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-8_1638953414952_0.8062754038901556","host":"s3://npm-registry-packages"}},"8.1.3-9":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-9","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-9","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"50bbf4885ca551035f75fdfcba913ce21f16c914","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-9.tgz","fileCount":9,"integrity":"sha512-8DVfQTpAnhzUEf/ZhDcuZJUEkNtvi4tZLqhlBJ7sB06q60H4cFB7R2+dPnfpb4bH/AC1hs33vWHJktt1DNWCcw==","signatures":[{"sig":"MEUCIDGYtKFz1iwaB+o8SRF/ngNI5fCGah61IVSpz4IRPqCdAiEApekkn6KEzW0BSQtdNZaMozlniyp78BU/8lYIF1px5w8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103479,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsH1mCRA9TVsSAnZWagAAbisP/3KfWsMpISb9kVkMW7WN\nS5EeaU1ITmGQAtMKVfHWGAXz+SgDuE4IMC+WRZRTwY/G2sJkrRxDj6wMGNnD\nO9O9bMH246u+ZARMyYo7LhKIWwv6YqXz7dueB14ulkR49xXBz3VuZ2NjPIYs\nxlJi1gOiXOx3D0Q4Ry03lbQSkax79uDxSDDcyAm41GKfNYrRKv3jh4N+KsHq\n4ZexRv3LHJ6ocYohEhwJjX0rX3STqS4d4mkNtDsOWVyeVqcbRkDZ+kO9DSOn\nKJQk52WDZef+CoNX5NJmBcJJW8bHQ57h/mg6tBdQQC+TwbQtIebBD0MNqFpj\nlkAQSnE0N6dyEs5AC79CcV48ZjEENBqUw805PdaMDyxC/hCWePCzaaij8da0\nwvN5C8zG2pSxWNQGw/s7k8fIWtZ4JxQGkvD+mVk/++VTPq6qVprSE6cLSPIQ\nLjlyCsREjYSiKSodDPZE+NyrEtxSjyzJDv5TYdiMbpwJNbc1i9atR3zugE1U\n+bAL50FH09ikTOOHPa0YVacSmfev85EcLJkGq/FpLkSDOrc0pfL0nVc4m7Bz\nPDZsAuGbV4W8YxW6nqKXssngBze/dwQ2ehWecdurM1i5VIizGJBadJF1/Tr9\nihrn+xt7OENtvR49MwfVn0nFf101JATsY0q67yE0a5x6NhXrxymJMgaVy48S\nC1SC\r\n=Dlfe\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"e019a3043acfb5bce6040ee0d74edffe65cf7181","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-9_1638956389998_0.7989755210314144","host":"s3://npm-registry-packages"}},"8.1.3-10":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-10","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-10","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"c6a85dca7ad9255eb1d0a9f58c1318abaa1a6e1e","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-10.tgz","fileCount":9,"integrity":"sha512-ohptPrrJb8hjmPoctB7DwbBV7qps0HWWszLFD0Fx3wnorWrS933MpjrvAah7b7BAoN+NYsPSgOVv8GoIR30ZAA==","signatures":[{"sig":"MEUCIQDt36GPAcZnsvrcAicw+FsQ6WAfCDzMepPRefPwy+hGigIgTBsSGOodhG1GuQkwGaT0nFnVe4gUFE2VUcqM2+RnXoM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsI6JCRA9TVsSAnZWagAAAPYP/2tnd6LeycefcDzTh4ti\noWqcvFT7ozYvxYDvZohIqidXQcRCk/PvTT/LlT8f+GsvfM5rqiaZG04kRplS\nTDRheZCLUwxkP7RgagosJlZ6WWn5bFSfAG0CKpEwnE6u8B+qNLbU3Cys0R67\n9R+0Kl/VbPxCp9e/LfTkjWc/w8WXT4PCH9tmqfSkuX/FCT9a3WAxHl+knZ20\naHBC4SFLoE5khBuLnjBizR5WFcVwc1wGyeSgsmS9BkAL4ILWXmPpC8CmgBYi\nVuZu/l8Gny5XYMK5iRRBxJC8zQr5Iy5enShX/fytjBWv+s8L0ZJOt5J8gFHj\njKqlpkSP/M6GYIc6dgDgGFRD09FqenDNS9j3C0LLEL74CE5SVwO9fxs5z9No\nmv2/ruaXlc7sm+mr5VWIu7SASBSdrOHTAUvgwPUWdCgUH8pxsETM1jQmpyW9\nc7BFLdvjqQaNQ0mZ1geTm6arwTdvWCVP5O6/7tjLDItn1O906Jm/lDMSIac2\nViPCnyAWdhKtknTrolGFOIVbYRIgAKl8s/bz/fIKob1INiVL8OC8/j7i3jvS\nnraN7qvmc8bhZFo8L4Es4N+a4cCSZ4XxtVnsZ1vpeU3YWy3UrkQWM62huIw2\nPJXdTjPJmOCUP3wtmwQdSjhpztDqjIIzuSncW48bFYt9k6oWP83cUk9v4LmX\nSFj0\r\n=RkWq\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"19ae0167231427fdd45206f055b60a826157a85b","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-10_1638960777714_0.5481094825059809","host":"s3://npm-registry-packages"}},"8.1.3-11":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-11","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-11","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"3e4366b0d40b8562d7529cb2b0ad1f76a64a14fa","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-11.tgz","fileCount":9,"integrity":"sha512-v8FZp5RLgvc463ixQXDU0wMLEOKanst/pgnT41A/ByRE3XmdpMUVtcUId/h0vt5AhhcczP82buqYY028+nzMjw==","signatures":[{"sig":"MEQCIAIvHlG2WI4R1HX8AcBKkUuSlX+3EksX41vt2Y7iRmbgAiBMrFWpkNF7b2bTFCTCze7tTk0ItQCBhQR0PbZ8XaLyQQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsJOUCRA9TVsSAnZWagAA9OYP/R2jDS0rY2FvkvY6B5rX\nVQxVwiUp61YcNwTINFQaAegoMbUVfVnddLKGENyKzTXv108QAG9+lS89AyEq\noisR4dIMxGHreAl5iC1NWSUcmcg4oPpPQgc+lpQL9c2kErcXmR0DxuLzElpW\nihwNNcjnqOd65wpy+k+e23YQrv5/CmjoHgXkQGjSC69WaM9uIW3MwAzEs90q\nKxIWrJQ7ospGm/Bv2LUKudo5mSDUtMOQzsyuRaVbC5O5dQocRIVLiWNPA1wB\nI3P/93xkbl20oji5pwk8DLhrHCdjCiVBLmGotg32j8GmYvEKDc5O5kBNWmSe\ntg2guwdzFQcXoyq1HClrH6kLqWN2rQGkizqesXFLwpqTWj5JoByFeR7FstK7\nFfgNs4hAjRTp2uRaUajH0Fv5rDb7aTqCesg5pmfWdg9kgIT4vmM+Sbjjp6e6\n77vAPbB0t1ljY5NXoXK5U5B/NdEZrA4lM+Ng7FmjoTI3ReDEOMjkB5IAQU4k\nZLlr4qzGBcs0pV/Kukcaj0YOkUjJw0RpS7kyc6EHfmBP69SSgcZmqa/SJbcw\nID1nj8TdWB48C6+/uX2z4P5YtalMpPm02mg6nAyGpDXHkmfoReK8IUShZWtO\nzm4jz+Xq0JuFtqn0qoB1PVvPo+937yJieHUD7peeHqdEnQzOpbu3kObWcOK+\nf+lD\r\n=i1If\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"5e48cfbbaa56012eb9a6433536f76b3e28741250","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-11_1638962068015_0.28337662839983957","host":"s3://npm-registry-packages"}},"8.1.3-12":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-12","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-12","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"7e281fd91013684bbe4ef976e937a8a61b3f44fb","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-12.tgz","fileCount":9,"integrity":"sha512-bfue5HhUaFzBqL3BP9fXhTWzmedyNPkjPer/slnC6qXu69059edme/wHBxAaCfI5x+yKauoXtquRfquEynHmYA==","signatures":[{"sig":"MEQCIDXD23WGU50/Z6iWcKehf2n8nzbbE0cwUzUzdzb+ivFeAiACeVuXdlKz1d6/Ncus5rLWR401QfIVk5oa8OBazuLgcQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsJUsCRA9TVsSAnZWagAAdMkP/AiHTRXckhcgDrK2U7sP\noeqWWqwD3IcC7BrLMtS2oIjj8c7Q2sYW/utyRkes+2ZxHgio5sTmEnGbS9gK\n4dix7KhOy88FzQBXYHQs0y10yVjq5quqEP+UWMtK49q2hUxXm1qiTs2VVNpv\n12ozpYU0w/ahXkyShCU2SWrdcmHQ4CgIAdLJhxwlpOoa3XYhM2o7pTf+q15d\nqUwBDe5tmRU1gaP0opDEfNgbrh2QYJ706tL6lsvGnf7YXu8NuLefe8GMPVBx\nPGAizP4GfwD9UGCkyFFmIpkmCrCI+kchQf/Oo/VaX/dqrqnYKsRhL67lh3s8\nYeGAO1Zv4syWeIJGGJg2fM0JKrMr7Qiqz+0u0q7ooJypmePT9HvwdZab8KOp\nzrXGeUEh/mt6lILe1H2RRJSOxgaxacSIlc0xmY5oearZYXIahPawmJfqfmgS\ng0a5EnonCoLy9+s26uxAikCPU4YjnXU4dsEIN3tVXWsoRiUEqDFDVzUvZph0\nhBzBZS3FfO4wnYasgffp+W/KedzVajGQDS6EO9M+KRcJeN1Lx6WU5Eq8/xWO\n2X1inW/sFrYXoEVo+hiYnLZhwfqbUWX4nzM6bJa+XQs5DqQARYXbznO6Jni/\nfo0WgMWyrlnQb8aIRK4Tpt6IZzs05UAdY502Ntf0MsrPROKGemqDYlXhuRyY\n+1Jm\r\n=LKx6\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"306e503d23aea2403fd066bcec7fcf8d5ed2b772","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-12_1638962476165_0.08478400075144732","host":"s3://npm-registry-packages"}},"8.1.3-13":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-13","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-13","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"0d990b29ae00cfd1f44ed7ad943fe74ca3ec96b0","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-13.tgz","fileCount":9,"integrity":"sha512-xOf/X4qJhUP75Ry5ihMWrXAYPhOw0ECO1bmSsjq/aWOPBJpgsCBVOKvustA5sA7WeyA6GbGy7cSLj6FFiylw1A==","signatures":[{"sig":"MEUCIQDgnlXezfEFz891b3V0FHMiwILoZir+0GdjhuJ70bLWfAIgWrcwkNU4pQ9Kd7DWsjZuGbRogJL7uoVuUg0uynOtoMQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsPmaCRA9TVsSAnZWagAAzQgP/0XtZm/IykvGRfAYRq82\nFPF1bU85vFgp55kAt7yxbmeQhUzvj47ghokuFrjwTYb3WjkInfgjYztkBiib\n95+eoUryZ/Vk/y5/7WcJbjrxTZRy5FLm4zCvTRetT+JloxPk0f4BXQNm30AQ\nzT4x0ARmA9sYossNeA7My1S82QS9q265WQXK8DbXGfLqbrHAysvW1CjgtWB+\n+PhUJRgBPAfw/o5ySJF6UpdUOQEDpZGRABbGx3efAnARM0iXMMrrhEgSpXzi\nzff8ppSLPBY0gHjftcycmcE5gOnYDNlMt1/r4XEUulg/BWSnv5x0X/E3CMQj\neB2dldxEJQqCPpD4xi4V7xcBC3CpUOopcr7YMHM+iz0EZz/OORJPuxWTnAVu\nZmUo5Al/+R7i3J5g0h0udgSYK3woQcu7xVtjnZIOfgfy473cWPN3c/9fXBbx\nNl9NVR1ARG1y/aRp9V8JzFXP3zI+w0jdpMtuybNclf9JhjMwjhXKQz//Zs54\nkgoIHquPzLZ1k526r4QE2Cpq/Hl178VTaXpR9iYJZD1zyCaa8YLNtBgZhPDj\nJbrh+IXlKFxm+AMbcbBl5uwbOK12CLYkzWKTJa9PilTGserOxQ817tKLnTew\ngpybzGTvMGdLB7JYkTiOT7VuQ7vUrBIHndx7ZiU5QANDdyt+YRzf7OMQsxBJ\n5IGM\r\n=DBds\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"000d097de297dc14281028b213f6156e631fc04b","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-13_1638988186756_0.3521530247229063","host":"s3://npm-registry-packages"}},"8.1.3-14":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-14","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-14","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"e2938bd73031127c4bfc6602585629e61a8b2c74","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-14.tgz","fileCount":9,"integrity":"sha512-EgyZZBv0qCkwMbedOjsdR32SMrV5kEVp2TC4ze0j9XHVVZVH+q25ZrN3tDV6h+ba8ui2tXA1iZtpbupTkf9CyQ==","signatures":[{"sig":"MEYCIQCV/bwXJJq1qB/gE3lXFSMUC0UuWw7plToVj37z3YWHBAIhAMhKNS9CfNFbGd4VEFDvswz9SHPJg2HO3VgK62gwsHvf","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsbtfCRA9TVsSAnZWagAAZ80P/RNSfle7S4xToKO/pu3C\n37h7A9LrSYi1hVJoUgR1Jc/bY0wIwpHQVRxtHyJY7gdz14qX2etp/ib3XuGg\nZuzYDEx6Kml04ZZETEejLvYQiaEoX5vWNO4N9dKpG8aObro8x5mYufjhI6IL\nVxfvLUWSXj0iD7e+JgoFSzKCsuP+uNLN8Ksxnu/lljzUOh228XT8JR/NYWG/\nje3kyBRYIRz7qaJ4pFtsQggj7VKmgk1VSD9A1obLJmpWwmRoMpg/9+jb4fwW\noN6wX57c2zqgxScFYoTw2HgOj9OFDaXASIf95f8QXiXmowCV2LeTw1fKPLrl\nHZZ7h5Kky2a2b+btaTqbk1zbGwsO44goQ7XoXwupihRBu73DCt4XK44I1IfL\n8HFzpqEtwdySpSQDjj1UoizEX0SWww7G1jgs80ill622t812a3tZSVo14h5Q\ntZ92NjNkAoV9obSCDleGp5VMcn01MpS4lLG6bLDXteOanEAYIZwvOsbGQ5GA\nqEg2ijD6Z/wnCmzh6zwEBGuo29SYyIAEuqnNVZabGFtEAus5RuH8RamJkABd\n0EENXh/xQVmlMgzsux0JtASqbP2hHlHDCCzbKXpnEllD5majjqFdvgSwouxH\ngq3CMfNXbOItZ7sQnvb9ckEgdR7WruJQCfhH7u/OwmeZljOHmcaIJAFCnEiL\n/mUF\r\n=0wAj\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"5ea69927049d6aaa094afc5cd9fdb639ebda32be","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-14_1639037791714_0.21210527346335262","host":"s3://npm-registry-packages"}},"8.1.3-15":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-15","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-15","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"59a9164b4a291a04141afce9440b28216e2684be","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-15.tgz","fileCount":9,"integrity":"sha512-UK+n4u4bGzd9EP2Ou7zGynoU+xD2U/XMWiTn6Nhz/R2EfjCIhEl41ldyH0vzDhdiqhjfHfX+pngr8y5Js+4lkw==","signatures":[{"sig":"MEYCIQClXKrctvElTK/h0PzlktTAERSg8G/8ZOJkAOHopSTvLQIhAMyqb5sudz6MXdtOx55NEu9a1GfHLPyEYidIK9sydl+t","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhscNTCRA9TVsSAnZWagAA/OQP/0/AyZM95YsXovQWpvsA\nUgjGdHNEqh85bgBXYHCEN5j7rHFPWVL5/cVc5b6Ql+D8AMGUbbjqdBgn6O2m\nBacMXR/71cQk99rWjeSqiDoWjCpY3lxIUy2tL821ThbiRciB5DEvobVWv99V\nU0vXeCsP/21RebnD1J+k5zl8oa+qREGr0fQh5hv3alwBeoozmdKHGHF336df\nFGI2+rVO++3aF2Z/hmKNwLcgvCoGw/l2Y9xcNTYo+eWfIjPu8iuo+QIjkPsw\nCWWrf/sudtceAZARFcQmTS2IHqd29RAKytg11NX+Yli2e0nqd5GBJqnpl+EC\nabYorcFlfwvZlLl4QmmhL2WAe17cqEJazA94YC/+44P4H/qOe473W+1Trpb2\nG/L9fByXxVbtKZtkMeiCeglACiSOI+/YXlAggAgZHgb7ucfDyznKGs3hSqz4\nOZ15GoZ7KBHfldK3wsL7ReeEImE9/CHyQ4VaVzPVSXdzKi3Iiaiu0rkDsk7l\nvVwDaIfoqsIChBlK7YMi6ZbWfajVjIm3QmX7E5VsVZtTWELmn54QemCKr2kL\n402fyOR5V4/Z9wd1Vxvn/a9rwrIX1DJCNCA/xeR69dSPX+1xoAr+dt2nJV7o\nEmGzT3dawzsx+VWXI9UqM+wqJU8p9knF2sSG4Isye0lAhRpgrIh4gJdMzbDF\nLJdl\r\n=/EWF\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"fbe1532f6254fdf5c96b1ef50c4587a0421cdba7","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-15_1639039827779_0.12072850328622886","host":"s3://npm-registry-packages"}},"8.1.3-16":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-16","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-16","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"2f2067a1d621a0693ae39774e106b64487b33a17","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-16.tgz","fileCount":9,"integrity":"sha512-mipU0607Ysch78BAqvru+PUxhc9hlOguKcuoituzJo+xy0CJSAYc3ionGbMiGO688rteRoidEwVZ8IVjB3px2g==","signatures":[{"sig":"MEUCIQDai2/MFrki7VDsq277BvW8JTThffOW3TwBdgDH8XebtAIgb5RTSgb9DLRLt2Fwbaq5l/PtAedwIQE0Yjp4lXOEWhI=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsk6qCRA9TVsSAnZWagAAIwcP/R5vr9InsyIVBV4aeIW+\npQRmpC5KtXIu+QjUVzyqCsy43HV9AJ8CY9LW4IYCOY+B20bNcY/4DJ4D5MdG\nDLbC1NtbSCkSXFGackZPgzOp7gXcADllTVHOYGfdrBthx8Zrs/xTRTPHmPmS\n5SmCnOOIcJneVELnv9pG++9nFhmXBlZCXwHTUrWTjDSI7Mt8gnSnxKdGeJHq\ng55hd5+eeKTgq8Fe+YcaXnbKvu09Tx3yLwDnF2xoLHPi2bpcaZUb87sRsMCC\nBkmwUiiLPluwoCKutfEL3z5E4ow9m2X84woVB5hBPP+dF16RhvUbwsV/vJB0\nRgx6ccOtOMTqvcg8Z/QllT1nDVihOVOlBqTqoGWP1HDOwzKZw76YIavXnr5R\nfwtYbTWlQrn8BrXbjGEgVTJbuRrOX8zDMGhBgwtkxuNz3CEX+ez4wkYNEvh3\nOfgrGWN/TSjN1XyxjE/yDDbdCFdiP8krJZXvPiBydD1rVR4GhJnDptnTeRrg\nu2N5bgTpb9dKcXEwMUWeMkKsF6jZkoWwtOYjwnX0v397U0YU+WwA192roAbj\nYClpMAPLaROK9gx1UvxBszDqqJSONsSZONWoQuegFSB6oroy6RHMfjVitYXx\n4Hq5UwhppiUxtQvn4ZCPBdAU8A2YunqXjXp7V38Z91dKKant3wFZogUB+rNF\nfXxH\r\n=0bl/\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"9efd2db37758fdac93a210cbe4c4aa3782daed46","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-16_1639075497941_0.9537669260154034","host":"s3://npm-registry-packages"}},"8.1.3-17":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-17","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-17","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"31b2a7fd3e53f854f058abd6caca04226543d8a0","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-17.tgz","fileCount":9,"integrity":"sha512-zKqP4xH4EBf+z85DdksqZHQyQq4CDVFyakjizA+j8/Ey88zylTvDlXZvsFlycvi+0V8rW8Et9PVNx3i78ULa7A==","signatures":[{"sig":"MEUCIC91OZ9m2VJkeR0bkmDYKhZ4NC/0nno0PkBrNkkLAXL0AiEAjPexur4NPjdjGb8K+fawlkVH52dp+Lu6J0W02JyDn5M=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsvhfCRA9TVsSAnZWagAA9McP/0DbdeGLocE6YYgnPKp+\nYaMsbSGr8CEBKEVd3AK7AUTCdERn7OWMlh0cjamGjRgQ3K1Diyz5DlA7SxSF\nU/qUrcKBMtO3lU9INAN7g15nrWRUgk0CCXXzo7HfYolvhmsZk66hhBKwpKbI\nN4ebN2GNmkY2Ux9I/+o0tRu1jtnDxl0pO4pg6p+NwZza08QQQFTnhaIYn9+0\nxMZT3bhkYRc9H8ee96rlF/1LsQhrPA7ig0xacNUiQEaY4AzWmYE9eoH9ykw2\nMy1zjoSgfjFvcEyaU3WNFIs5NRIlxa/JOqeyLPnOjAXabqvlu4siHf8mGd1a\n8x4Q7K9XoLWbRfKyymlon0c5DpJJonFZX076FRsD6X772ej0hVp/yS5Unbi5\nAvA8Z3BDspZLcqLVFVWYKtLLDpIBs8qQIeUuUrXwZntV6gKoHMhdm8IY5NiL\n6mKzHZzQclhZvSCeq+OLI8OwF+PrO6BSSEdpSSZPUlYgH+gbJqNneYD7UUXb\nOhK+/dSrVmJExBm2V50H2G6Y6hkHKgkAxHZRSuZIomzckeDmIzocwJbu7f63\nbH9YfZlvtVx44hGACxa5YXKanrMrciE3rMcUOhUdeOCecFdSjd6ssMT3b84t\nwOktwnLkOIqLntHMfyJg82HlAbYp55QYS5DZCmp816+034vbrAl8YrHwpNVc\noes3\r\n=U+oE\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"c673b96963667f45fd3b2c996ffe6200773e10ac","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-17_1639118942910_0.5464970858037401","host":"s3://npm-registry-packages"}},"8.1.3-18":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-18","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-18","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"726909fc4d74f3e5118f502be4825b896f99a13b","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-18.tgz","fileCount":9,"integrity":"sha512-yoNvOi9Ba0a3PyPf0avRWIRxiXNUkMjE3VGFRzgdtUKFXnzf0q/9pqJaExFGFX8lS8EEh1Ay3KmWNLsEaGXcOA==","signatures":[{"sig":"MEUCIQCg+ISVJgf6GBP0KYyjbNBcVBsk7GscpXXyGq74MR5qpQIgRy6BQQquADen40jk5TJNIaE7/4f2jcYGjYP9bxHmlt8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsxutCRA9TVsSAnZWagAAj0oP/0P4Hn6UcIcmVWuYSOAL\nJS4uDGUuQqGGylv3VqiWzyefx/G+1rRlmW6rgDnkRHPrsBYxTzwHE2DG54yU\n421QX8/PGtSAwZM2NGrn1cRyAJX8t5ByRpBv0H9OHaEur55UilHX29WM3IwG\ne/MdgZDKN7/uITmL98ip4048Bx73HRUhEc72mz0kx7bpSo2TC0E9lN4HfU36\nN7VCHs/gHCoK6FJkkByUL5NKVJ2wnsMnKGQYQ2vBYXf9OUEUhqIOc4EYw/9c\nQleCd7KjN3cxDYdbEgDeXnHbESw8CKRKjn/9jzN+rGKX0wI3mBM3/Jj1N7Nb\nUyHmYkrvFbYV5LIVk+fZCu3yVDeMQR8kv2DtanWeynA0cl1ORZC8EpRH2rx5\nQ7TwUsEG91+it4aQUWsz6X+JaVR3uwqIZ7SzvTfhp+ZSAUpVr5n6l1zC2JjP\nIQ3xsSkAekB4De/kjLijCEyKE/ly269oPQ2w/kUI99kpJ3wleJnNpzxnFccU\nXwH8hAB9sv70ZOA6+moaU+wQ2soj8PsEu1X7j8wTcDHonlGLmOhHcluzz0p/\nhf6Rf3hKhzjXiTpyWYiqCzx3SABHZL0II0XL+Cyce3kqjZmZXmu4UZXixP3H\n84jnoDd2IpX/R1iGhwkrNyR8Rc21LfxHju5xHztYBzJQ/NRiFCfubvy2QYVy\nj+4J\r\n=UfGt\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"4d3a2d96106934ba80dc67c56eb8794580f006df","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-18_1639127981455_0.7110437656962838","host":"s3://npm-registry-packages"}},"8.1.3-19":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-19","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-19","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"6dfb3211e6b34786b64990b53ba89484af53688c","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-19.tgz","fileCount":9,"integrity":"sha512-8zAB+RDBnhgVySuCbcv96bcf1ZY8FtNnm88eL5DHRFX2Ff5BaqJFzPIkA80y4u4De8kOhZJpoIauE9klafYorg==","signatures":[{"sig":"MEUCIA33bOua0AhlW0usBbWXIDZJlgwAxYD1UWeEfd2OLeyZAiEAhkwRiQSOwU0SfHjkO9Tg5KdSo/KU3uuYJHxgAt1W0gg=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhsx9OCRA9TVsSAnZWagAAKmAP/0zE39MAyni/aNJfdrGD\nzlGZIQPuRLme47ZKIuXVyKJ0MpY4NfSH6+wCSRQLtFHZ8CRDaDjmplxJDxrP\nCydUujpdh8y5C4MOqwPwV3pHweJUDeAGkmz3yDa4sA54nafGcNKaJwVm6T5W\nNjZ4V7slzmCxWvtcTU8Y53Wx6R5mQb/Rl98PzayM0rZRXMb6DveJZ0suRKuz\nSAxugxX/gHaQ0P1xbX5BY78xlGC7t6iX+xbvHnY04KNaBRIS2d0J9Qfm15CN\n99EBZzwQ3IaH/45s2VNdEEXi7H5bDzwD7nhz+AfSrlHvYkX9QOs9DV7i0/iD\nbR/VLEgFVkgukRfEmgcH+hB/GLdCJlQBZ2LlwX3uliqc0PETfr4EhC5EXOGg\nzoGoGmGwr5CIm7Vyyqo3CBl2QinnbX2LaNdaOIPqxN8TZpLMhGkubXy4CsNI\nmze5Nj0+dVTxIegKEFifa0d7T//ChyMoOuvHrJ1gqvsoJKwEPjbvbP8ydpPH\npt+nMS0Bmwl7GJ5UqFJFDwCwH8Z308QUjOEJ4g4en+xIdWgVpxLRGRKtjlqm\n02zb2GIwzKNLQV0TNeqIRqr8tg/nvnP++1FlWW8h5UEcTJbxS6Gqm2UibKVA\n90vMMC6x5ckSaugiecCT75QYFilPWvDdg0pGMsV3hEozoNYwYn6Gi9jPfHkW\nrdzd\r\n=x5YH\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"5bf71dab41aedbfee07d9eea6d3ab68093700351","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-19_1639128910268_0.7361343803390825","host":"s3://npm-registry-packages"}},"8.1.3-20":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-20","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-20","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"72b2a2a44afc0ee587f759a8994c50ffd43e434b","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-20.tgz","fileCount":9,"integrity":"sha512-/t0YBsEvzMuk75ZD+v1+qKjJlFiMmFTz/v1dxBcygrCaQ+SSQ1r4SUWYaAXNJXtAsxSrRxbkH9CheGUJ7Wu81Q==","signatures":[{"sig":"MEUCIDN81RJwDEhNBnG72qGjB/boZ++dDH9/IcPPdFaInTaaAiEA6Xp5FGQT3dN+zeOShama6I8G+3YFJ/tQaE4WaP3rG38=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhtFh7CRA9TVsSAnZWagAAegkP/0oL7nNonuBS8I//VE6N\nihzZ2rAoLmAa3Y/1IvZpa3/+TlNrqr9nHg9mgzapS8/4E1YzL93ztiq0Vqin\nIlXOk0VpgV7UjSC52FgJzIY1YWWMhiaGVXbKDtNiuy1Kkm6vHzi8yVnchf4p\nPGE/g1NsZsjGoAriVafoNf8HlQwXc8LGEcBhs//BSdZD1CMtzpl3G+XR0Hwe\naQpb+7o7q+N86EYrpSa9YRFuxxKJQyrnQvpr7kpvVdTwtkPf1PkAEtinLkok\nN0SmfG4K/1+l4IH+L0qhjKzGdr4qFlaYfQZKtw1k3qcedE3a454R3NpCWUJb\nqTKfdI9rRYnRr3LNIvYopNCNY9I/zVt45eOWUY+K3T2dE2OP+xRZDhESVYOc\nTpH8adeC4FLHy8EWNvjexSMqDuKPpdm/q5i9nzsUXIt3l/yDVfdAfzu/NSLw\nKAWaNwpt9P73yRcY7dMZNbqzjozrxrpSQzIve3GV4LrVPbvkKEctZMDsER7J\ntaaFwGAS9p/asynSTp/PDLLQhR3oLRDaY/BFCx+9izSaJkVPPYEDsbF64f+Y\nQlyBd0smgbBY5S9GSWepTwzSJHjwjjue++dp43gatGKps7CAYUMekqdbRNXU\nHqvBzG4VOpFqVRDEVGcg5QnHWM6eF1Cv6xelSXpW7yCHqi/pMKfhygOAGytn\nV3km\r\n=Hvqf\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"88d1a71df84c7958b8e195e5f47ace93d99d31c0","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-20_1639209082885_0.8042157995663017","host":"s3://npm-registry-packages"}},"8.1.3-21":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-21","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-21","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"5ebb7cc36ec9c85421966e2cb629b0aeccea0823","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-21.tgz","fileCount":9,"integrity":"sha512-ooIgh+ldkqOac+6wEgdtdbnfmsszL4CE5SH+al/1lMyMnDi3nTCIy+zK+z0zywKgg7kDcQijCNgdMuxuYQHaGA==","signatures":[{"sig":"MEUCIC4TVVY81vjhVSAlq6PTHyo9FCdqOMRZDiRdx/nJfzarAiEApqzUsctwO8bRNIuuH3auJbj0+2RsGzJTaKq2CIBQOfs=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhtZtuCRA9TVsSAnZWagAAeAgP/1uJEEWSLZM+NghMvwS2\nwhBUGHIAe31kNnK3Yw9hC1kJ5VLrb7AzzCIWMx5kHpe1jcz/rAjU3zKcpHMk\npU/SFUGvuN7D5TGH3zr7L0/7r1QVZI8YfXlO3P2zQMCzNMo7qt/5jB5VPY0n\nmRDVjfQgFJuMOVNo6vEHv0Ah5QNm3Nw3hogDjsCoRGaBy0+FTnyOPAafCGSn\nQTmB3mpFMI4LLYTGCd3XnSW2vRHH53Mxc3Jlm0jLqrpQzU9i0LguY5pI3Jmf\n0h3EArivyLeio6zr+BTn/CK5Ie5SGB7XUDXdSFsfjmux1EW7evoLlIorLivC\n4okqaC+B0EIfVsLbEG05XDsPryNCXBWWDTCjgLvz5cCo6Xp+H9dgi6GSeIgw\nytOGJoT5mvfPLAblruwz97brQkKKxKdb7YJCciSyhEDggJs6m4dJxhEz+2VC\nUVmRyasgrruZuN77vjepFLQyYmLQST6yXHeDrzXRy0sSvoBeqOKlIyyOfrXk\nc6Jrus+0E6bz8/sHFMFAu/FtJjAtCzpzPNO4pwFiHgLYGLAATlGbaIJJiBla\nhyvBUg91Bs3EIQ5OU1SEgxYy6r/Jqct/jikBLqY8Vt0+nLjFlqUYMa4ZQU2k\njsPmy238fUna8AHRfVG6sxOvagdPAlNoA0X1CBEII/zCChfP64Vz647MNlXz\nTVcP\r\n=0t3S\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"227a34d55dca87a5adc363f236d796e393f3f257","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-21_1639291757979_0.519561268626624","host":"s3://npm-registry-packages"}},"8.1.3-22":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-22","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-22","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"385ff21784b610f00584453873605dee9e2ad106","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-22.tgz","fileCount":9,"integrity":"sha512-evS3i32SDxLF52DRvLkMFVFX64oDLWq5pmtdxGsru3m+1t02MUEsK2/o+lXQ5/0B/76ZYmiX0Zhj6lb7FlSSJQ==","signatures":[{"sig":"MEYCIQC6hgdSfMxlv/q9ou6eUA7KE6pHoeLJZ2YZfJDyejECBAIhAMMvAVsxKIADHVDpItXih1ktNDgua8qe1rZaFUvfYnw+","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhtcG4CRA9TVsSAnZWagAAYHkP/iJyLNzaHyACWvaitkYi\n1pPO/q9vwSSbgwSHxrVCqqsLkeT409xjWJCiw6YyE/kk1FvQyPTtC+vXnyji\n2g2Gxwx6f09S6LinumhF2GbPsThyE4shtNvmF1NtR681f+Cuw1RcQpfm4KbZ\nTt78BuvEs2NlQpMBoFwf7LIShQSb+nXvK4xPAs9KVVigJW3m+QIHKxqXmiAU\nnuBaQGoVscqb5Csh0PMIkb1eeT7fDSO7CCCFWjaJcInC34mHRM9Fm+UTaYVk\nMeisGZg9VWZs1a6Es+Mjojh6oB/3SPd5JBCJ5cvtxvWwLi05ZCpiazVF0Mhg\nI2f/mCpHlWknN/sZaUyeLH5nDm9jhqhTPclN1eDpF+WWVkYE56pgy0RgqFEJ\n+PL78b1mjjg6m8adxzdTQ9G3DIfqxh3V3/DE2xt1pV+I5a+CObbxg/H3+obZ\nTXNW2rmMvp4jLtbf9+xmp2XjSAtOPNOz/q3rZ2AcV4A44x21YvpFwRtHiziK\nV5Bw9mZRF5ff/QpSevC+TnVFNyGfl+OI4GVAQnGI0lFrzz6tk7G0Afuy77ll\n7wCuN64gNUACvgWoyAjsZwADufFn0c9cBrM2evTcpPEMvnAECY5SZcSCnGyA\ns6XjgbOhL7WiYBI0AFRfJ2TEPqRKhPYRZESRmxPMDHExVLUhtKzFNRFvf6js\nGS0X\r\n=NNLE\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"7d46eb8423fd851df14279932d3ad081f3374d4c","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-22_1639301560281_0.8502536592333279","host":"s3://npm-registry-packages"}},"8.1.3-23":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-23","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-23","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"6e94a2da95807cbe1f996b046821ff0fdf7744c5","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-23.tgz","fileCount":9,"integrity":"sha512-/4UeCpTjd4YabEUiydIA4Jhnx9FQgtOCAcF7iwEa40wFICNdzrXuZezmmIt8no2/Udu0pM8XRloVB3UWZxXVsQ==","signatures":[{"sig":"MEYCIQDNTzzV9PzvxVyoptC2HMJ63c7aZ/w3g5BuNP/APgUjDQIhAIrRdxRGFv9RBhnwIlMG55Jxd+e6xvhMhrs3N+yj7ki4","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhtuXXCRA9TVsSAnZWagAAMQIP/icqhlsWJuUtBfZpCuN+\nijIHq3qYmNpkoj0+ecnLyO5nPESXiXRCn9ML8QFVdO3u1JhQriAtY8WD0BeR\ns9zKUA1LGnpvDSe1gDXGlHxsVdCmxFSLqNG7r2xLwspNBaA62GfwIavRpcnR\nh8NVYcEPR1xJSovqklcHtL0fTsYkB5WxKdj2z8L9QlfwKuheXSSRSuPUsFER\nrfLC5oXoBZkc/aHBk0wxPZxKk348HyUbO5ShsIAIEfE9OXWdRAO468idDE0K\nPJYheL1xGjd51ynN7JICKSAjtIcxu4X03xQ+eBf4nVZDbn8nh5+EGHW7VTqx\nQFYIRwMRKamcS0hatvTAfzvjzCkJf+L19foTc3A6IiwQFIIMzcEMVll5CTm7\n1/K0M+BEXxA2LlYKHJRt5RrLIb8CsrOSjq6Y50sKsBz8kAwsSRfitDWBR000\ni4moJu9etkFdGRXBeHW/1HeJAG36MfJ2pl83OsWpkACHUcEDDtfTUUhqDIfS\nj16/c0WU7ABVBn4rHiwyiiAYvOZv0+gde6pDUQluEYeipwaVyuwrc3Xwwie9\nCEKDkXWyLf9PFPWFAzXP5CupZcxgNX7ivwLImcHDAomBVivOWcJ9g80LMzQh\nl9f4jRtiKXyLqDY119wBu+ntC8fl6eZk0zLH4WGwLS9Yov/kwvnFymuXYLqt\nMqfB\r\n=NIJV\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"1f9a1a5f8a3b78a56581a69e8a1b489a3cc8607c","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-23_1639376343633_0.14753994525552638","host":"s3://npm-registry-packages"}},"8.1.3-24":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-24","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-24","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"d0b6e1443e30cf0c3df0cc61474f3f3e5f7e6662","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-24.tgz","fileCount":9,"integrity":"sha512-tGAPRBTYxseNdPlSMm/75KQQqxWWvT4t4uT6V3SOEvFRAQTlHrv9jOiIuarYfwg2Z7H5xj5Z7SGcGeLITLiMYA==","signatures":[{"sig":"MEUCIGMDs1E4j3fVJ8K7mmvHrNiAbeHopXG0Q7ynuoJoVaI7AiEA2aSq1DczNpcWxrJ+0sAHUs+008w6g1t7OQPp6HbbLG8=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhtwFzCRA9TVsSAnZWagAAU4kP/3+iIKGogwiui4Kqy93t\nFWK8Me2k8L3W9P+C6huojLV10wJrUFjyQdVUYJ3kdHIg2285RO+Ot3pIGMcK\n0CVt6sLVhto7WjbmUp+un2uUcZ6M+gfaWcvugYUAeFhyxqmkpF2zju3U8lSX\nYIXixysLCgLA49hEIfQPke7nNbcpoIctrHd5aRkBChc8/tu1gThCYq2Xt54X\nOcHaPHRtqF4As+9vfda14HdGOiU5ikSXzHCj4T65x/cq1wFyPQW/EQC64UgK\nYzP7uNgg7LCqdMq0ljA5a5sIzw9Zf9Ke4oW7pxBUKiIku/hTppWR5sU2pnPK\n1epgatYeUgd+FYIp1rL1mawv7R6hhHgT0k2koKRwcUvQ3ACc1zGgX2KYd9fC\nGp7n/aeefc9UjDVmPf2jasdkT0+k3p4PTHk4E6T841VRXFD56Ewf7+T2bxqV\nPWNhRoIsYmux5EEI0SVYgYXLlCjftPPw1tngRY7v6sQ0wgnNSoiYvX6l2aEK\nXaOXiwOzeaE3uaz83/iIUZDDh1M5S7Zjs88a+FjWaL5aZ3eBZ5bAgIvz0BUp\nbJb/ZNZ/sP65+K/KgV1v9heEDPkBlbFd+5yiRTlaPVbikZICOQ8LB53TBlVf\n9GsTdKSVcw+q9UFdtpG8lyMJY/Rg2qPRFtm6YE0yTOsqugh0Os6biAt5AMm3\nSDgf\r\n=GJUD\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"3802426046ff73df9ac7852c2ab357118ab44cb9","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.0","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.0","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-24_1639383410862_0.6569313064251634","host":"s3://npm-registry-packages"}},"8.1.3-25":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-25","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-25","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"2e8edf2b7eb570a350aad32c8ac02c97107a0a91","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-25.tgz","fileCount":9,"integrity":"sha512-tqk6alty1YDFNLy9G9LsxsfLmDEz1vZ4Xvu5W3Lp8nFBJ4sQ4aKrV7KakQ2HWMHE1JdxkqWDihkRY0ienXKBxA==","signatures":[{"sig":"MEQCIGNE8noYjLkKIGFMsT+Q5Y0IECKaAWdamNrPY2ZwvIX0AiB181V3dVcDGTK6AkRLFYWMb5UBw64jrHlTyjQ0I1wjMA==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJht29ICRA9TVsSAnZWagAAa4EP/R5qIpcoKHepaDCR8fXw\n/mugGawnlYAzh5ai6DnGbxS/zehbPJQzz/3MR4R7kghjRGkOMcVvAcSsZE0V\nAxlDTr9TVPEcGZ9w+Ihoc9mbW/t7dPt/mPrDbJ6w5CJNPxNSFqiJBl/izrh8\nNe6LTRL8XLrh5cztOStRmbcg34AG9mPd+uoqoNStyiSyT/d6xSGvWC7jf6SJ\n5JuzTSwubDzgsZswjo0qEywsCYBHKCrOiFozI7Trjk9ivmW2MctpoWbukBrH\nsmp5NyXSJCgQp6XzjKSFw5X+Yx7c67wQhPUnrvL8xQMLaaIiZmptiQS9XnOo\np6kiXchq9eHafwh+qFRxYOSKngyEWLRUlB5yQrnkl95/CZkws+KIjEJykdpt\nefTMWfaPL3KN06/6UJKV+sqzt4vwm4cH4pSHzC+y7orCxBteyRIRaJBtAitp\nTIRaqcBIFurxZOJbclSZEIiqrl8A/AXLLARs8uRV91L/LqRiuCNBywvIQxMx\njD+OY32Yh9HILF2jvBBF9Pig0BGHH6BrVfmIdkkqqd7SbGoqaTZL4EssuU7w\nmVBsOjJ078qQ43guPZ4vPXD30LurSSfv2J4DQGEX5dVpPD9pnbP5INhSt8gX\n9x4Lzar+zyv8aCUGKBreL06M6xX0IUdQgBgFFO9EdikKplMWtW4J/+zTfpnJ\nkcOF\r\n=rtME\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"6154454c3821d18ce699c84e5e3946e9464fb85b","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.2","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.1","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-25_1639411528233_0.10760501099189912","host":"s3://npm-registry-packages"}},"8.1.3-26":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-26","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-26","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"541d7a44f3d3e93456681cc23a9d04e093f69d59","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-26.tgz","fileCount":9,"integrity":"sha512-IsZxIbFoePI+Homsy5I4cUhcRgLWugoZr25TIoYMC1GFpJp7fUJHuflk5YOf7r02FIn8I7uo53Igr/1PK8Fn9w==","signatures":[{"sig":"MEYCIQCcdLttLtwEVaIEkhFXWVD8+keQT61WSkCEDuB5jC3pPQIhALk7MP6W78VsFeL/qENyPh5Clp+3CaBhDVsQj/kWfIcE","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJht3EzCRA9TVsSAnZWagAAAFsP/jvVJkScFAKBNqPk/rVI\ntRb2bVdlmkdlc6tdaLSJvQ8y/mvPSOMe9ckBZZy61ndojO7vQrKRxkyIRg8t\nNyy5/aOeLKaw99ERF8qjjMEBFKwSb2mk44MU18imUB0ISRZoLEBxRtKkNPxd\nGnkcZXzy1kxk1+kULA1Pfx0M2t64TLekQ4LFrdX0OwO3ZlMKKuGZyQOSHOAb\n2NtSpqk29mmbMklUnH0tgdf+WS2o6GVOEIW8BIbSteqBrCAmkBiSqXI261DI\nJw0+e3LSg54c6bVyNWEtfWl7hU/y4sF+6hdi8lw5+siDeE15z3EvgJqbsbzL\nSQnPCod8HPMSJpYnjZ+As4pk7H09sAODVunx5wXN+d4JI5rxyCiNkjkfVo9B\nCpHa9nTJf907QHDPTXYvwS+EKg+8HEQ0fWgfrkNCkkNFH2DdC+b1Z2A3SjJc\nJkS6AWaamLYYYio9jjifKEz1xIpjGAs5XR0Yx4z6MU+KJwljo0Q5xGGR+JI8\nV7nDYn9KzK9A9yrhdO0HYSWfu3CBEFcFKVjnRO3ZBY+4OFunyy9jFotwbJOh\nQ28TPk7cwqMAsgjRpo8Uf0nkjNdI1LomferIHAfnkfZ+WyZl8P/sQVqu1Hr0\nclczUJGzWNFGZG+kZIvir3SjJgVNLggyGlVDjR6sPFM/CI/2AGBxIxPf2J+C\npdRv\r\n=Nw49\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"fdd32df12f94180dfb3c9c3dbcb4bd6913f38c93","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.2","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.1","dependencies":{"@babel/runtime":"^7.16.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-26_1639412019365_0.42040320167811074","host":"s3://npm-registry-packages"}},"8.1.3-27":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-27","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-27","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"a1c2cdcc20cdbfaa8f29914a0536c74e68b81bc8","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-27.tgz","fileCount":9,"integrity":"sha512-abykeYyoEKPCTlYf2vkgnFfvQFlzNUk+oVr51CYfUNSwmoU81K96A9TbAKVxVVR+6VtTodBcsxoW/pdOV7eOyA==","signatures":[{"sig":"MEQCID2LgY7N6/rvluB55yTiVruZZh2lZvg10pIt9UjgvLsbAiBCDVlfgkjK1u9pt1My7w0Qcaf6Xp4WNOOAbCOJTJ4cLw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhuDl7CRA9TVsSAnZWagAAF0oP/Rq/K4r9npua5sioe8Rx\ncmqz1Xv+04OcBwkBXlC/5u93V2jSabeyXRgXpYvCOvGGHzabvUJb/o//YUUo\no7iDr1qxSMrU50x+op3Bhp37Xn7C/Wb1ApdOQX792qy8Bk3j370EoaPlUD1k\nwfkQ9Fffd6KNR2fAU0SxPBUS6yiMbtmXnU8p7H+/5+Fkj8GwYcSRPLGu20sl\nbFdmPUFcaxosKmmlBjDTFEJGf9gq+HzoI4edOYTGCY98RUnBM9s+YDvo1KMl\nfgOC8BlNrXFRR2cvw9FCwh7o7GyrQW/8KHF0gPWnohAEE199yZzVXMsJXLmU\nmt22yHLJI2SDcCVi6pH18u26O+maotb7ualTWBLdAot9RJlxgnERCD3bfXt5\nPNKQu1oP7+AhBWpRJCw/BS8HGpDUK/QZFwU6RSt8WdDuJsbLFcSsFh4ggDF9\nY6eg3QKlVMLlJ+/wJf8AQQ2aUsPO/0bW73vbT+tjZOD6V2Aw3nUECS7yzvYO\nLgVkphm0XjTetNISEnd3u5lpH8QG6jbcDy7PQCCZ3PupMiVTCzDEHuTWKviy\nPUWlu3Qor7LJ/BAe9YdSops8C9SygjcA+IPFc27vJhFX9GpmNJ67hu12h7CL\nTUu6sY3qDp79JB3/aSBNSkSK7LzXT1TTbRYXgSyPZ5K3ichexDpSiUQi8gUU\nvN13\r\n=mEVl\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"d83e50ee19492c1bc5fa360b836e4ab021c97bec","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.2","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.1","dependencies":{"@babel/runtime":"^7.16.5"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-27_1639463291239_0.9972547259781848","host":"s3://npm-registry-packages"}},"8.1.3-28":{"name":"@polkadot/x-noble-secp256k1","version":"8.1.3-28","author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","_id":"@polkadot/x-noble-secp256k1@8.1.3-28","maintainers":[{"name":"jacogr","email":"jacogr@gmail.com"},{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"}],"contributors":[],"homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","bugs":{"url":"https://github.com/polkadot-js/common/issues"},"dist":{"shasum":"e06bea3739f5d2b9288eecaf9b9f981a55a106b3","tarball":"https://registry.npmjs.org/@polkadot/x-noble-secp256k1/-/x-noble-secp256k1-8.1.3-28.tgz","fileCount":9,"integrity":"sha512-74mVI2Rlwkf2BEnWgaJecydFvTF5kJYpTv+N3iCydKdo6RNWWFtJw0WoNC1cspH9cMKLmpo87FWyxbMLBJYp0Q==","signatures":[{"sig":"MEYCIQDPERpNtm+pqPHoNio6sAjSSeOp6PsjYJgy0aIFRtValAIhALxLoWGKY/8C9eDL7JMl33FacTU/re3tGa3XYcb+JjZF","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":103482,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhufRSCRA9TVsSAnZWagAA0noP/jTsRtbl6RIcDeo5pFZB\nZK/cZNmo/JGk3ZplXhIas8a1FQBq1uq7AWGY9MqLLW7EJ8TxcrAtk5M88g/1\nzZ48agolf+lN+eYjYSYfKBNADU4kP+Bbpo8vbiHdFp97yh/+FyfbQVQW7WEZ\noRviFSWABMsiNS2RF8TqMi2dLpTanoFzA5eTp6VMEbIQJQPw8IkYvcB2FN8E\nlQd11FKSnYe0XLunHd6A7X6qz5oOsjq2Y7hhCChgFTFhJbGTrtG2E9dJcjm4\nIImCrcOKsJkRFjYs77P1e+NPSsd3Pc797BQqcMRUWE1NnQX/OMTE7WTQHdRN\nm6SohIGmJL0+YkjBZXU8G2BNqzYwumyBwVWr1SBfIhrmHZa0M99Q/fQ/20/2\njiYETICFt/eEodActbDxaJxUxIENM+ioPB4Lju26gLm8qo4BQO9x2P1xN9dV\nJm/DeiRY5fYcXfDUrsUdVxfX5qITdRWVyF9IaDm7kjF9/AQ2qDtDjOvlD4l4\nilN5qvOCe63Kvvy2oGOCr6tOL6ytwOoo+kICEFw3YsAWmnIfdMaCz7NkqzIl\njNneMG0otjOXdXu6ZCuMz/4g2z85UYwyjdST4DkAgfK9eaAarAAIv+D1Vze0\nJgqDutQIC0QF3yf6DS4C0Oe68z2oS5/jk4ztb4JAcZ6o5LkWSH+aBkPHvE4N\nYIbX\r\n=zdJk\r\n-----END PGP SIGNATURE-----\r\n"},"type":"module","types":"./index.d.ts","readme":"# noble-secp256k1 ![Node CI](https://github.com/paulmillr/noble-secp256k1/workflows/Node%20CI/badge.svg) [![code style: prettier](https://img.shields.io/badge/code_style-prettier-ff69b4.svg?style=flat-square)](https://github.com/prettier/prettier)\n\n[Fastest](#speed) JS implementation of [secp256k1](https://www.secg.org/sec2-v2.pdf),\nan elliptic curve that could be used for asymmetric encryption,\nECDH key agreement protocol and signature schemes. Supports deterministic **ECDSA** from RFC6979 and **Schnorr** signatures from BIP0340.\n\n[**Audited**](#security) with crowdfunding by an independent security firm. Tested against thousands of test vectors from a different library. Check out [the online demo](https://paulmillr.com/ecc) and blog post: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/)\n\n### This library belongs to *noble* crypto\n\n> **noble-crypto** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- No dependencies, one small file\n- Easily auditable TypeScript/JS code\n- Supported in all major browsers and stable node.js versions\n- All releases are signed with PGP keys\n- Check out all libraries:\n  [secp256k1](https://github.com/paulmillr/noble-secp256k1),\n  [ed25519](https://github.com/paulmillr/noble-ed25519),\n  [bls12-381](https://github.com/paulmillr/noble-bls12-381),\n  [hashes](https://github.com/paulmillr/noble-hashes)\n\n## Usage\n\nUse NPM in node.js / browser, or include single file from\n[GitHub's releases page](https://github.com/paulmillr/noble-secp256k1/releases):\n\n> npm install @noble/secp256k1\n\n```js\nimport * as secp from \"@noble/secp256k1\";\n// if you're using single file, use global variable nobleSecp256k1 instead\n\n(async () => {\n  // You pass either a hex string, or Uint8Array\n  const privateKey = \"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\";\n  const messageHash = \"a33321f98e4ff1c283c76998f14f57447545d339b3db534c6d886decb4209f28\";\n  const publicKey = secp.getPublicKey(privateKey);\n  const signature = await secp.sign(messageHash, privateKey);\n  const isSigned = secp.verify(signature, messageHash, publicKey);\n\n  // Supports Schnorr signatures\n  const rpub = secp.schnorr.getPublicKey(privateKey);\n  const rsignature = await secp.schnorr.sign(messageHash, privateKey);\n  const risSigned = await secp.schnorr.verify(rsignature, messageHash, rpub);\n})();\n```\n\nDeno:\n\n```typescript\nimport * as secp from \"https://deno.land/x/secp256k1/mod.ts\";\nconst publicKey = secp.getPublicKey(\"6b911fd37cdf5c81d4c0adb1ab7fa822ed253ab0ad9aa18d77257c88b29b718e\");\n```\n\n## API\n\n- [`getPublicKey(privateKey)`](#getpublickeyprivatekey)\n- [`getSharedSecret(privateKeyA, publicKeyB)`](#getsharedsecretprivatekeya-publickeyb)\n- [`sign(hash, privateKey)`](#signhash-privatekey)\n- [`verify(signature, hash, publicKey)`](#verifysignature-hash-publickey)\n- [`recoverPublicKey(hash, signature, recovery)`](#recoverpublickeyhash-signature-recovery)\n- [`schnorr.getPublicKey(privateKey)`](#schnorrgetpublickeyprivatekey)\n- [`schnorr.sign(hash, privateKey)`](#schnorrsignhash-privatekey)\n- [`schnorr.verify(signature, hash, publicKey)`](#schnorrverifysignature-hash-publickey)\n- [Helpers](#helpers)\n\n##### `getPublicKey(privateKey)`\n```typescript\nfunction getPublicKey(privateKey: Uint8Array, isCompressed?: false): Uint8Array;\nfunction getPublicKey(privateKey: string, isCompressed?: false): string;\nfunction getPublicKey(privateKey: bigint): Uint8Array;\n```\n`privateKey` will be used to generate public key.\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n`isCompressed` (default is `false`) determines whether the output should contain `y` coordinate of the point.\n\nTo get Point instance, use `Point.fromPrivateKey(privateKey)`.\n\n##### `getSharedSecret(privateKeyA, publicKeyB)`\n```typescript\nfunction getSharedSecret(privateKeyA: Uint8Array, publicKeyB: Uint8Array): Uint8Array;\nfunction getSharedSecret(privateKeyA: string, publicKeyB: string): string;\nfunction getSharedSecret(privateKeyA: bigint, publicKeyB: Point): Uint8Array;\n```\n\nComputes ECDH (Elliptic Curve Diffie-Hellman) shared secret between a private key and a different public key.\n\nTo get Point instance, use `Point.fromHex(publicKeyB).multiply(privateKeyA)`.\n\nTo speed-up the function massively by precomputing EC multiplications,\nuse `getSharedSecret(privateKeyA, secp.utils.precompute(8, publicKeyB))`\n\n\n##### `sign(hash, privateKey)`\n```typescript\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<Uint8Array>;\nfunction sign(msgHash: string, privateKey: string, opts?: Options): Promise<string>;\nfunction sign(msgHash: Uint8Array, privateKey: Uint8Array, opts?: Options): Promise<[Uint8Array | string, number]>;\n```\n\nGenerates deterministic ECDSA signature as per RFC6979.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `options?: Options` - *optional* object related to signature value and format\n- `options?.recovered: boolean = false` - whether the recovered bit should be included in the result. In this case, the result would be an array of two items.\n- `options?.canonical: boolean = false` - whether a signature `s` should be no more than 1/2 prime order\n- `options?.der: boolean = true` - whether the returned signature should be in DER format. If `false`, it would be in Compact format (32-byte r + 32-byte s)\n\nThe function is asynchronous because we're utilizing built-in HMAC API to not rely on dependencies.\n\n`signSync` counterpart could also be used, you need to set `utils.hmacSha256Sync` to a function with signature `key: Uint8Array, ...messages: Uint8Array[]) => Uint8Array`. Example with `noble-hashes` package:\n\n```ts\nconst { hmac } = require('noble-hashes/lib/hmac');\nconst { sha256 } = require('noble-hashes/lib/sha256');\nsecp256k1.utils.hmacSha256Sync = (key: Uint8Array, ...msgs: Uint8Array[]) => {\n  const h = hmac.create(sha256, key);\n  msgs.forEach(msg => h.update(msg));\n  return h.digest();\n};\n\n// Can be used now\nsecp256k1.signSync(msgHash, privateKey)\n```\n\n##### `verify(signature, hash, publicKey)`\n```typescript\nfunction verify(signature: Uint8Array, msgHash: Uint8Array, publicKey: Uint8Array): boolean\nfunction verify(signature: string, msgHash: string, publicKey: string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n##### `recoverPublicKey(hash, signature, recovery)`\n```typescript\nfunction recoverPublicKey(msgHash: Uint8Array, signature: Uint8Array, recovery: number): Uint8Array | undefined;\nfunction recoverPublicKey(msgHash: string, signature: string, recovery: number): string | undefined;\n```\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `recovery: number` - recovery bit returned by `sign` with `recovered` option\n  Public key is generated by doing scalar multiplication of a base Point(x, y) by a fixed\n  integer. The result is another `Point(x, y)` which we will by default encode to hex Uint8Array.\n  If signature is invalid - function will return `undefined` as result.\n\nTo get Point instance, use `Point.fromSignature(hash, signature, recovery)`.\n\n##### `schnorr.getPublicKey(privateKey)`\n```typescript\nfunction schnorrGetPublicKey(privateKey: Uint8Array): Uint8Array;\nfunction schnorrGetPublicKey(privateKey: string): string;\n```\n\nReturns 32-byte public key. *Warning:* it is incompatible with non-schnorr pubkey.\n\nSpecifically, its *y* coordinate may be flipped. See BIP0340 for clarification.\n\n##### `schnorr.sign(hash, privateKey)`\n```typescript\nfunction schnorrSign(msgHash: Uint8Array, privateKey: Uint8Array, auxilaryRandom?: Uint8Array): Promise<Uint8Array>;\nfunction schnorrSign(msgHash: string, privateKey: string, auxilaryRandom?: string): Promise<string>;\n```\n\nGenerates Schnorr signature as per BIP0340. Asynchronous, so use `await`.\n\n- `msgHash: Uint8Array | string` - message hash which would be signed\n- `privateKey: Uint8Array | string | bigint` - private key which will sign the hash\n- `auxilaryRandom?: Uint8Array` — optional 32 random bytes. By default, the method gathers cryptogarphically secure random.\n- Returns Schnorr signature in Hex format.\n\n##### `schnorr.verify(signature, hash, publicKey)`\n```typescript\nfunction schnorrVerify(signature: Uint8Array | string, msgHash: Uint8Array | string, publicKey: Uint8Array | string): boolean\n```\n- `signature: Uint8Array | string | { r: bigint, s: bigint }` - object returned by the `sign` function\n- `msgHash: Uint8Array | string` - message hash that needs to be verified\n- `publicKey: Uint8Array | string | Point` - e.g. that was generated from `privateKey` by `getPublicKey`\n- Returns `boolean`: `true` if `signature == hash`; otherwise `false`\n\n#### Point methods\n\n##### Helpers\n\n###### `utils.randomPrivateKey(): Uint8Array`\n\nReturns `Uint8Array` of 32 cryptographically secure random bytes that can be used as private key. The signature is:\n\n```ts\n(key: Uint8Array, ...msgs: Uint8Array[]): Uint8Array;\n```\n\n###### `utils.hmacSha256Sync`\n\nThe function is not defined by default, but could be used to implement `signSync` method (see above).\n\n###### `utils.precompute(W = 8, point = BASE_POINT): Point`\n\nReturns cached point which you can use to pass to `getSharedSecret` or to `#multiply` by it.\n\nThis is done by default, no need to run it unless you want to\ndisable precomputation or change window size.\n\nWe're doing scalar multiplication (used in getPublicKey etc) with\nprecomputed BASE_POINT values.\n\nThis slows down first getPublicKey() by milliseconds (see Speed section),\nbut allows to speed-up subsequent getPublicKey() calls up to 20x.\n\nYou may want to precompute values for your own point.\n\n```typescript\nsecp256k1.CURVE.P // Field, 2 ** 256 - 2 ** 32 - 977\nsecp256k1.CURVE.n // Order, 2 ** 256 - 432420386565659656852420866394968145599\nsecp256k1.Point.BASE // new secp256k1.Point(Gx, Gy) where\n// Gx = 55066263022277343669578718895168534326250603453777594175500187360389116729240n\n// Gy = 32670510020758816978083085130507043184471273380659243275938904335757337482424n;\n\n// Elliptic curve point in Affine (x, y) coordinates.\nsecp256k1.Point {\n  constructor(x: bigint, y: bigint);\n  // Supports compressed and non-compressed hex\n  static fromHex(hex: Uint8Array | string);\n  static fromPrivateKey(privateKey: Uint8Array | string | number | bigint);\n  static fromSignature(\n    msgHash: Hex,\n    signature: Signature,\n    recovery: number | bigint\n  ): Point | undefined {\n  toRawBytes(isCompressed = false): Uint8Array;\n  toHex(isCompressed = false): string;\n  equals(other: Point): boolean;\n  negate(): Point;\n  add(other: Point): Point;\n  subtract(other: Point): Point;\n  // Constant-time scalar multiplication.\n  multiply(scalar: bigint | Uint8Array): Point;\n}\nsecp256k1.Signature {\n  constructor(r: bigint, s: bigint);\n  // DER encoded ECDSA signature\n  static fromDER(hex: Uint8Array | string);\n  // R, S 32-byte each\n  static fromCompact(hex: Uint8Array | string);\n  toDERRawBytes(): Uint8Array;\n  toDERHex(): string;\n  toCompactRawBytes(): Uint8Array;\n  toCompactHex(): string;\n}\n```\n\n## Security\n\nNoble is production-ready.\n\n1. The library has been audited by an independent security firm cure53: [PDF](https://cure53.de/pentest-report_noble-lib.pdf). The audit has been [crowdfunded](https://gitcoin.co/grants/2451/audit-of-noble-secp256k1-cryptographic-library) by community with help of [Umbra.cash](https://umbra.cash).\n2. The library has also been fuzzed by [Guido Vranken's cryptofuzz](https://github.com/guidovranken/cryptofuzz). You can run the fuzzer by yourself to check it.\n\nWe're using built-in JS `BigInt`, which is \"unsuitable for use in cryptography\" as [per official spec](https://github.com/tc39/proposal-bigint#cryptography). This means that the lib is potentially vulnerable to [timing attacks](https://en.wikipedia.org/wiki/Timing_attack). But, *JIT-compiler* and *Garbage Collector* make \"constant time\" extremely hard to achieve in a scripting language. Which means *any other JS library doesn't use constant-time bigints*. Including bn.js or anything else. Even statically typed Rust, a language without GC, [makes it harder to achieve constant-time](https://www.chosenplaintext.ca/open-source/rust-timing-shield/security) for some cases. If your goal is absolute security, don't use any JS lib — including bindings to native ones. Use low-level libraries & languages. Nonetheless we've hardened implementation of koblitz curve multiplication to be algorithmically constant time.\n\nWe however consider infrastructure attacks like rogue NPM modules very important; that's why it's crucial to minimize the amount of 3rd-party dependencies & native bindings. If your app uses 500 dependencies, any dep could get hacked and you'll be downloading rootkits with every `npm install`. Our goal is to minimize this attack vector.\n\n## Speed\n\nBenchmarks measured with Apple M1.\n\n    getPublicKey(utils.randomPrivateKey()) x 6,121 ops/sec @ 163μs/op\n    sign x 4,679 ops/sec @ 213μs/op\n    verify x 923 ops/sec @ 1ms/op\n    recoverPublicKey x 491 ops/sec @ 2ms/op\n    getSharedSecret aka ecdh x 534 ops/sec @ 1ms/op\n    getSharedSecret (precomputed) x 7,105 ops/sec @ 140μs/op\n    Point.fromHex (decompression) x 12,171 ops/sec @ 82μs/op\n    schnorr.sign x 409 ops/sec @ 2ms/op\n    schnorr.verify x 504 ops/sec @ 1ms/op\n\nCompare to other libraries (`openssl` uses native bindings, not JS):\n\n    elliptic#getPublicKey x 1,940 ops/sec\n    sjcl#getPublicKey x 211 ops/sec\n\n    elliptic#sign x 1,808 ops/sec\n    sjcl#sign x 199 ops/sec\n    openssl#sign x 4,243 ops/sec\n    ecdsa#sign x 116 ops/sec\n    bip-schnorr#sign x 60 ops/sec\n\n    elliptic#verify x 812 ops/sec\n    sjcl#verify x 166 ops/sec\n    openssl#verify x 4,452 ops/sec\n    ecdsa#verify x 80 ops/sec\n    bip-schnorr#verify x 56 ops/sec\n\n    elliptic#ecdh x 971 ops/sec\n\n\n## Contributing\n\nCheck out a blog post about this library: [Learning fast elliptic-curve cryptography in JS](https://paulmillr.com/posts/noble-secp256k1-fast-ecc/).\n\n1. Clone the repository.\n2. `npm install` to install build dependencies like TypeScript\n3. `npm run compile` to compile TypeScript code\n4. `npm run test` to run jest on `test/index.ts`\n\nSpecial thanks to [Roman Koblov](https://github.com/romankoblov), who have helped to improve scalar multiplication speed.\n\n## License\n\nMIT (c) Paul Miller [(https://paulmillr.com)](https://paulmillr.com), see LICENSE file.\n","browser":{"crypto":false},"engines":{"node":">=14.0.0"},"exports":{".":{"default":"./index.js","require":"./index.cjs"},"./README.md":"./README.md","./index.d.ts":"./index.d.ts","./packageInfo":{"default":"./packageInfo.js","require":"./packageInfo.cjs"},"./package.json":"./package.json","./packageInfo.d.ts":"./packageInfo.d.ts"},"gitHead":"96a019f6eb0f45cc4ad9c02f786d5d4cb5d0a7a8","_npmUser":{"name":"polkadotjs","email":"polkadotjavascript@gmail.com"},"repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"_npmVersion":"8.1.2","description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","directories":{},"sideEffects":false,"_nodeVersion":"16.13.1","dependencies":{"@babel/runtime":"^7.16.5"},"_hasShrinkwrap":false,"readmeFilename":"README.md","_npmOperationalInternal":{"tmp":"tmp/x-noble-secp256k1_8.1.3-28_1639576658416_0.2595236351187433","host":"s3://npm-registry-packages"}}},"time":{"created":"2021-12-03T13:48:23.135Z","modified":"2026-02-02T15:42:01.094Z","8.0.6-13":"2021-12-03T13:48:23.309Z","8.0.6-14":"2021-12-03T14:29:16.155Z","8.0.6-15":"2021-12-03T15:30:08.666Z","8.0.6-16":"2021-12-04T07:17:15.303Z","8.0.6-17":"2021-12-04T11:03:04.833Z","8.0.6-18":"2021-12-05T08:16:00.991Z","8.1.1":"2021-12-05T08:59:27.357Z","8.1.2":"2021-12-05T11:21:23.074Z","8.1.3-0":"2021-12-06T05:10:21.387Z","8.1.3-1":"2021-12-06T07:06:58.581Z","8.1.3-2":"2021-12-06T08:29:11.375Z","8.1.3-3":"2021-12-06T12:46:46.540Z","8.1.3-4":"2021-12-07T15:43:25.925Z","8.1.3-5":"2021-12-07T16:16:23.156Z","8.1.3-6":"2021-12-07T17:51:03.364Z","8.1.3-7":"2021-12-08T08:33:16.269Z","8.1.3-8":"2021-12-08T08:50:15.139Z","8.1.3-9":"2021-12-08T09:39:50.186Z","8.1.3-10":"2021-12-08T10:52:57.870Z","8.1.3-11":"2021-12-08T11:14:28.159Z","8.1.3-12":"2021-12-08T11:21:16.316Z","8.1.3-13":"2021-12-08T18:29:46.945Z","8.1.3-14":"2021-12-09T08:16:31.850Z","8.1.3-15":"2021-12-09T08:50:27.937Z","8.1.3-16":"2021-12-09T18:44:58.104Z","8.1.3-17":"2021-12-10T06:49:03.097Z","8.1.3-18":"2021-12-10T09:19:41.595Z","8.1.3-19":"2021-12-10T09:35:10.426Z","8.1.3-20":"2021-12-11T07:51:23.065Z","8.1.3-21":"2021-12-12T06:49:18.178Z","8.1.3-22":"2021-12-12T09:32:40.538Z","8.1.3-23":"2021-12-13T06:19:03.829Z","8.1.3-24":"2021-12-13T08:16:51.006Z","8.1.3-25":"2021-12-13T16:05:28.392Z","8.1.3-26":"2021-12-13T16:13:39.521Z","8.1.3-27":"2021-12-14T06:28:11.381Z","8.1.3-28":"2021-12-15T13:57:38.625Z"},"bugs":{"url":"https://github.com/polkadot-js/common/issues"},"author":{"name":"Jaco Greeff","email":"jacogr@gmail.com"},"license":"MIT","homepage":"https://github.com/polkadot-js/common/tree/master/packages/x-noble-secp256k1#readme","repository":{"url":"git+https://github.com/polkadot-js/common.git","type":"git","directory":"packages/x-noble-secp256k1"},"description":"An fork of @noble/secp256k1 with extra protection on BigInt usage","contributors":[],"maintainers":[{"email":"jacogr@gmail.com","name":"jacogr"},{"email":"polkadotjavascript@gmail.com","name":"polkadotjs"},{"email":"cicd-team+npm@parity.io","name":"paritytech-ci"}],"readme":"","readmeFilename":""}