NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1811 most downloaded on npm
Audited & minimal JS implementation of elliptic curve cryptography
Last release 1 months ago
27 Aug 2026
Ships unpredictably
gaps range from 8 days to 7 months
Nearly every release is documented
notes for 27 of 27 stable releases
27 versions withdrawn
withdrawn after publishing
4 years old
54 releases · first in 2022
One column per quarter.
This is not a vulnerability; it's protection against those who don't follow the FROST spec. Spec wants user to preserve rounds.
0x00 encoding.Special thanks to Red Team (Rob Hamilton, CalleBTC, Omer Talip) and 1Password's Off-by-1 Labs.
Full Changelog: 2.3.0...2.4.0
Hardened constant-time execution from best-effort to actual guarantees: no measurable timing behavior on 200K samples. Scalar multiplication now uses
It was possible to execute a remote timing attack on X25519, across many samples, and learn up to 4.036 bits of long-term private key. Other 247 bits were NOT affected.
The impact: mainly fingerprinting (recognition of key across deployments), NOT key recovery, NOT X25519 breakage. Maintainer was also not able to escalate to co-residency (SMT).
Reported and found by:
geostergiop@aueb.gr)kpatsak@unipi.gr)secp256k1.Point.BASE.precompute(8) (likewise for other curves).Full Changelog: 2.2.0...2.3.0
It was possible to execute a remote timing attack on X25519 across many samples and learn up to 4.036 bits of a long-term private key. The other 247 bits were not affected.
The impact is primarily fingerprinting—a key can be recognized across deployments—not key recovery or a break of X25519. The maintainer was also unable to escalate the attack to co-residency (SMT).
Reported and found by:
geostergiop@aueb.gr).kpatsak@unipi.gr).getPublicKey by 2.7×.getPublicKey or sign call by approximately 2× for Ed25519, P-256, P-384, and P-521.getPublicKey and sign became slower because the window size was decreased from 8 to 6 and constant-time execution was hardened. Long-running applications that prefer 2.2.0-level speed can restore it with secp256k1.Point.BASE.precompute(8), and likewise for other curves.March 2026 self-audit (all files): no major issues found
Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>TS2345(We're skipping v2.1, to align with other noble packages)
Full Changelog: 2.0.1...2.2.0
Object.freeze to most primitives.Uint8Array, while TypeScript 5.9+ made it generic: Uint8Array<ArrayBuffer>.TS2345.Version 2.1 was skipped to align with other noble packages.
Disable extension-less imports. If you've used /ed25519 , switch to /ed25519.js now. See 2.0.0 for more details.
/ed25519, switch to /ed25519.js now. See 2.0.0 for more details.rootsOfUnityThis GH release does not include standalone noble-curves.js: use 2.0.0 for now, until we upgrade to newly added Immutable Releases
Full Changelog: 2.0.0...2.0.1
/ed25519, switch to /ed25519.js. See 2.0.0 for more details.package.json to ensure TypeScript autocompletion.package.json changes.map_to_curve_elligator2_curve25519 for Ed25519 in #211.try/catch around pairingBatch in bls12_381.verify() by @MegaManSec in #212.rootsOfUnity.This GitHub release does not include the standalone noble-curves.js; use 2.0.0 until the project upgrades to newly added GitHub Immutable Releases.
Breaking changes of ECDSA (secp256k1, p256, p384...):
v2 massively simplifies internals, improves security, reduces bundle size and lays path for the future. To simplify upgrading, upgrade first to curves 1.9.x. It would show deprecations in vscode-like text editor.
.js extension must be used for all modules
@noble/curves/ed25519@noble/curves/ed25519.jsisValidSecretKey, isValidPublicKeyPoint.fromHex now expects string-only hex inputs, use Point.fromBytes for Uint8Array{prehash: false}{lowS: false}{format: 'der'}.signature.toBytes(){message: ..., publicKey: ...}[]weierstrass() + ecdsa() / edwards() + eddsa()pippengerp256, p384, p521 modules have been moved into nistjubjub module has been moved into miscabstract/curve.js submodulePoint.BASE.multiply() and Point.Fn.fromBytes(secretKey)*curve*_hasher.secp256k1.hashToCurve => secp256k1_hasher.hashToCurve()pasta, bn254_weierstrass (NOT pairing-based bn254) curvesFull Changelog: 1.9.6...2.0.0
Version 2 substantially simplifies internals, improves security, reduces bundle size, and lays a path for the future. To simplify upgrading, first upgrade to curves 1.9.x, which surfaces deprecations in VS Code-like editors.
.js extension must be used for all modules.
@noble/curves/ed25519@noble/curves/ed25519.jsisValidSecretKey and isValidPublicKey to Weierstrass and Edwards curves.misc.Uint8Array; hexadecimal string inputs are prohibited.
Point.fromHex now expects only hexadecimal strings; use Point.fromBytes for Uint8Array.sign and verify now expect unhashed messages instead of message hashes. Use { prehash: false } to restore the old behavior.sign and verify now use low-S signatures by default. This does not affect secp256k1, which has used low-S from the beginning. Tests against specific signature vectors may fail after upgrading unless { lowS: false } is used to restore the old behavior.sign and verify now use Uint8Array signatures in compact format by default.{ format: 'der' } in verify, reducing malleability.verify now prohibits Signature instances; call signature.toBytes() first.getPublicKey, sign, verify, signShortSignature, and related methods into bls.longSignatures for G1 public keys and G2 signatures, and bls.shortSignatures for G1 signatures and G2 public keys.verifyBatch now expects an array of { message, publicKey } inputs.weierstrass() + ecdsa() and edwards() + eddsa().Fp became p.Point class and hash.Fn argument from pippenger.Field#fromBytes() now validates elements to be in the range from zero through order minus one.p256, p384, and p521 modules into nist.jubjub module into misc.ExtendedPoint and ProjectivePoint to Point.px/ex, py/ey, pz/ez, and et to X, Y, Z, and T.Point.normalizeZ and Point.msm to separate methods in the abstract/curve.js submodule.Point.fromPrivateKey(); use Point.BASE.multiply() and Point.Fn.fromBytes(secretKey).toRawBytes and fromRawBytes to toBytes and fromBytes.RistrettoPoint to ristretto255.Point and DecafPoint to decaf448.Point.toCompactRawBytes and toDERRawBytes to toBytes('compact') and toBytes('der').toCompactHex and toDERHex to toHex('compact') and toHex('der').fromCompact and fromDER to fromBytes(format) and fromHex(format).randomPrivateKey to randomSecretKey.utils.precompute and Point#_setWindowSize with Point#precompute.edwardsToMontgomery to utils.toMontgomery.edwardsToMontgomeryPriv to utils.toMontgomerySecret.*curve*_hasher; for example, secp256k1.hashToCurve became secp256k1_hasher.hashToCurve().Point#multiplyAndAddUnsafe and Point#hasEvenY.CURVE property with miscellaneous internals. Point.CURVE() replaces it but provides only curve parameters.pasta and bn254_weierstrass curves; this does not affect the pairing-based BN254 curve.Field.MASK.utils.normPrivateKeyToScalar.Nothing published for this version
Nothing published for this version
Nothing published for this version
More deprecations and preparations for v2
toMontgomeryPriv => toMontgomerySecretFull Changelog: 1.9.6...1.9.7
toMontgomeryPriv to toMontgomerySecret.SignatureConstructor for Weierstrass curves.edwards: expose nBitLength, nByteLength
weierstrass() method (still lazy, waits for first call)tower from v2Full Changelog: 1.9.5...1.9.6
nBitLength and nByteLength for Edwards curves.secret and public to secretKey and publicKey in the experimental CurveLengths interface.weierstrass(), while retaining lazy calculation until the first call.tower implementation to BLS.Fn fields with different BITS lengths.More preparations and deprecations for future v2 release
Full Changelog: 1.9.4...1.9.5
secp256r1, secp384r1, and secp521r1 from #203.CURVE.nByteLength from #202.Add more deprecations for the upcoming v2
Full Changelog: 1.9.3...1.9.4
ProjConstructor.There are lots of renamings and API adjustments; but all old code would work as-is. The code would visually flagged as "deprecated" (using jsdoc flag)…
The release contains bugfixes and a few improvements which pave the way for upcoming v2.0.
There are lots of renamings and API adjustments; but all old code would work as-is. The code would visually flagged as "deprecated" (using jsdoc flag) in typescript-supported code environments, which makes it easy to upgrade to new versions.
*privateKey to *secretKey everywhere for consistency with post-quantum and non-noble librarieskeygen method to curves which creates both secret and public keyssecp256k1_hasherFull Changelog: 1.9.2...1.9.3
This release contains bug fixes and improvements that pave the way for version 2. Existing code continues to work unchanged, while old APIs are visually flagged as deprecated through JSDoc in TypeScript-aware environments.
*privateKey to *secretKey throughout for consistency with post-quantum and non-noble libraries.keygen, which creates both secret and public keys.fromBytes and toBytes to Weierstrass signatures and deprecated fromDER, fromCompact, toDERRawBytes, and toCompactRawBytes.edwardsToMontgomery into utils.toMontgomery.ED448_TORSION_GROUP for Ed448.curve.info to all curves for better interoperability.sqrt9mod16 to modular arithmetic._hasher properties, such as secp256k1_hasher.Fn) and curve fields (Fp).The release contains bugfixes and a few improvements which pave the way for upcoming v2.0.
The release contains bugfixes and a few improvements which pave the way for upcoming v2.0.
Fp and Fn static properties which are its fieldsbls.longSignatures and bls.shortSignatures APIs
sign() logic for k generationFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.9.1...1.9.2
This release contains bug fixes and improvements that pave the way for version 2.
toRawBytes to toBytes.ExtendedPoint and ProjectivePoint to Point.Fp and Fn field properties to Point.bls.longSignatures and bls.shortSignatures APIs.
randomBytes and HMAC from noble-hashes by default.sign() logic for nonce generation.multiplyUnsafe and stopped using multiplyAndAddUnsafe for Weierstrass curves.abstract/fft - new experimental implementation of FFT (Fast Fourier Transform) / NTT
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.9.0...1.9.1
abstract/fft.getSharedSecret argument validation for rare Weierstrass curves.The release contains bugfixes and a few improvements which pave the way for upcoming v2.0.
The release contains bugfixes and a few improvements which pave the way for upcoming v2.0.
.js extension
@noble/curves/ed25519@noble/curves/ed25519.jsFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.8.2...1.9.0
This release contains bug fixes and improvements that pave the way for version 2.
.js extension.
@noble/curves/ed25519@noble/curves/ed25519.jsnist module.inv0 throughout hash-to-curve to ensure zero elements are returned in exceptional cases.FpInvertBatch creating sparse arrays instead of arrays containing undefined.Important: this release adjusts wNAF scalar multiplication logic
Fp12 fields typeThanks to @ChALkeR for spotting edwards bug.
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.8.1...1.8.2
z = 0; zero points have z = 1.CURVE.a definition for Ed25519.mapToCurve.Fp12 fields type in tower.misc module containing Jubjub and Baby Jubjub.Uint8Array toHex and fromHex when available, providing a 13× speed-up on 256-byte arrays and a 20× speed-up on 32 KB arrays.erasableSyntaxOnly.Thanks to @ChALkeR for spotting the Edwards bug.
Use typescript verbatimModuleSyntax to support future node.js type stripping
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.8.0...1.8.1
verbatimModuleSyntax to support future Node.js type stripping.The package is now available on JSR.
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.7.0...1.8.0
isolatedDeclarations option, which substantially simplifies automatic documentation generation and more.
isLE logic and reversed mapHashToField in modular arithmetic.curve: add wnafCachedUnsafe() and precomputeMSMUnsafe().
multiplyUnsafe to new wnaf methodsformat option in verify, choose between compact and derFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.6.0...1.7.0
wnafCachedUnsafe() and precomputeMSMUnsafe() to curves.
multiplyUnsafe now use the new wNAF methods.sqrtP calculation until its first use instead of precomputing it at initialization.format option in Weierstrass verify, selecting between compact and der.isBytes performance.weierstrass, edwards: add multi-scalar-multiplication using Pippenger algorithm
abstract/tower for pairing-friendly curvesFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.5.0...1.6.0
abstract/tower for pairing-friendly curves.Implement bn254 (aka alt_bn128) pairings, compatible with EVM and ZEC
toAffine and assertValidity, to speed-up BLSFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.4.2...1.5.0
toAffine and assertValidity to speed up BLS.Typescript build: revert target from ES2022 to ES2020 due to compat issues
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.4.1...1.4.2
bls12-381: Add mapToCurve; fix typescript types
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.4.0...1.4.1
mapToCurve to BLS12-381 and fixed TypeScript types.Fix verification of BLS short signatures when using hex
Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.3.0...1.4.0
tsconfig.Add support for short signatures. Short sigs allow using G1 as sig and G2 as pubkeys, instead of wise-versa.
Group interface for DecafPoint and RistrettoPoint by @sublimator in https://github.com/paulmillr/noble-curves/pull/85weierstrassPoints missing CURVE object by @secure12 in https://github.com/paulmillr/noble-curves/pull/92hexToBytes: speed-up 6x, improve error formatting by @arobsn in https://github.com/paulmillr/noble-curves/pull/83isBytes: improve reliability in bad environments such as jsdomconcatBytes: improve safety by early-checking the typeequalBytes: make constant-timeFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.2.0...1.3.0
Group interface for Ed25519 and Ed448 DecafPoint and RistrettoPoint by @sublimator in #85.CURVE object in Weierstrass weierstrassPoints by @secure12 in #92.hexToBytes by 6× and improved error formatting, by @arobsn in #83.isBytes reliability in environments such as JSDOM.concatBytes safety by checking types early.equalBytes constant-time.weierstrass: improve security of random private keys by decreasing bias from 2^-64 to 2^-curve_security_level
2^-64 to 2^-curve_security_levelsideEffects: false to package.json,
add pure annotations to ed25519Full Changelog: https://github.com/paulmillr/noble-curves/compare/1.1.0...1.2.0
2^-64 to 2^-curve_security_level.extraEntropy to accept any number of bytes.sboxPower mandatory, allowing only 3, 5, or 7, and prohibiting odd roundsFull values.Uint8Array DSTs in hash-to-curve.sideEffects: false to package.json and pure annotations to Ed25519.ed25519 and ed448 verify now provide non-repudiation (Strongly Binding Signatures) when option zip215: false is used
verify now provide non-repudiation (Strongly Binding Signatures) when option zip215: false is used
weierstrass: sign return type was changed from SignatureType to RecoveredSignatureTypeedwards: rename edwardsToMontgomery to edwardsToMontgomeryPub, add edwardsToMontgomeryPrivFull Changelog: https://github.com/paulmillr/noble-curves/compare/1.0.0...1.1.0
verify now provide non-repudiation (strongly binding signatures) when zip215: false is used.
sign return type from SignatureType to RecoveredSignatureType.edwardsToMontgomery to edwardsToMontgomeryPub and added edwardsToMontgomeryPriv.ristrettoHash size typo in hashToCurve by @sublimator in #42.utf8ToBytes in Firefox extension contexts.First stable release. API should remain stable now.
First stable release. API should remain stable now.
ed25519, ed448: changed API
context is now an option in sign and verifyzip215 is a new verify option that allows to conform to RFC8032 when false. For true it will instead match ZIP215.edwardsToMontgomery functionbls12-381: changed API
CURVE is no longer exposed, it was an internal property. Use G1.CURVE, G2.CURVEfields: {Fp, Fp2, Fp6, Fp12, Fr} propertyweierstrass: improved DER decoding. Validate curve creation
Updated Wycheproof vectors to v0.9
hash-to-curve: restrict expand to xmd and xof
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.9.1...1.0.0
First stable release. The API should now remain stable.
context is now an option in sign and verify.zip215 is a new verify option that conforms to RFC 8032 when false and matches ZIP 215 when true.edwardsToMontgomery.CURVE is no longer exposed because it was an internal property. Use G1.CURVE and G2.CURVE.
Fields moved into the fields: { Fp, Fp2, Fp6, Fp12, Fr } property.
See the README for new usage.
Improved DER decoding and validated curve creation for Weierstrass curves.
Updated Wycheproof vectors.
Restricted hash-to-curve expand to xmd and xof.
Fix React Native like environments: remove bigint literals
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.9.0...0.9.1
abstract/modular: Fp is now Field
weierstrassPoints initializationFull Changelog: https://github.com/paulmillr/noble-curves/compare/0.8.3...0.9.0
Update hashes and devDependencies
Update hashes and devDependencies
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.8.2...0.8.3
Common.js support has been brought back
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.8.1...0.8.2
Invalid release, re-published as 0.8.2
Invalid release, re-published as 0.8.2
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.8.0...0.8.1
ESM-only; remove support for common.js modules
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.7.3...0.8.0
- hash-to-curve improvements Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.7.2...0.7.3
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.7.2...0.7.3
montgomery: add randomPrivateKey
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.7.1...0.7.2
Nothing published for this version
Move output from lib to root. React Native does not support pkg.json#exports
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.6.4...0.7.0
Typescript fixes Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.6.3...0.6.4
Typescript fixes
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.6.3...0.6.4
Small hash-to-curve improvements
Small hash-to-curve improvements
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.6.2...0.6.3
- Refactoring, bug fixes Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.6.0...0.6.2
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.6.0...0.6.2
Nothing published for this version
Removed 2d (x, y) affine points. Use points in projective xyz or extended xyzt coordinates instead. Affine points were a simple abstraction around the
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.5.2...0.6.0
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.5.1...0.5.2
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.5.1...0.5.2
hash-to-curve: add xmd/xof support
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.5.0...0.5.1
hash to curve for weierstrass curves
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.4.0...0.5.0
- BLS signature support - Strict checks for private keys Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.2.1...0.4.0
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.2.1...0.4.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Ristretto, schnorr for secp256k1
Full Changelog: https://github.com/paulmillr/noble-curves/compare/0.1.0...0.2.0
Initial release of Short Weierstrass curve
Initial release of Short Weierstrass curve
Your coding agent can read these notes before it upgrades. Set up the MCP server →