# Crypto contract bug?

**URL:** <https://forum.flow.com/t/crypto-contract-bug/1264>\
**Category:** 🏄🏻‍♀️ Cadence\
**Created:** [March 9, 2021, 8:51pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264 "2021-03-09T20:51:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![MatthewW](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@MatthewW](https://forum.flow.com/u/MatthewW)\
**Post date:** [March 9, 2021, 8:51pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/1 "2021-03-09T20:51:17Z")

</div>

On the [docs page](https://docs.onflow.org/cadence/language/crypto/) for the crypto contract the example uses `ECDSA_P256` as the signature algorithm, but the API for the contract mentions the `ECDSA_Secp256k1` SignatureAlgorithm.

I’ve tested with it and get the error  
`"decode public key failed: the signature scheme UNKNOWN is not supported".`  
when I call `keyList.isValid`

Is there a bug in the contract, or am I misinterpreting the error and there’s a problem with my code?

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [March 9, 2021, 9:18pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/2 "2021-03-09T21:18:19Z")

</div>

Hi Matthew!

Good question, this could be a problem with your code or a bug on the Cadence/node software side.  
Could you please post the code you’re trying to run and which produces this error? That would allow us to investigate the issue. Thanks!

---

<div class="post-metadata">

**Author:** ![MatthewW](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@MatthewW](https://forum.flow.com/u/MatthewW)\
**Post date:** [March 9, 2021, 9:52pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/3 "2021-03-09T21:52:50Z")

</div>

Here’s the code I’ve been running. I’ve generated the signature and signedData using web3js’s web3.eth.accounts.sign/web3.eth.accounts.hashMessage functions.

```auto
import Crypto
pub fun main() {
    let keyList = Crypto.KeyList()
    let publicKey = Crypto.PublicKey(publicKey: "63d6820c82a9e31dffa9a876b328d9f26f2757f808243498b8ab158165e27d79607ffac074dfc65861adaad9ff14084fce020d9cf60cb1b971b9d176d0a41756".decodeHex(), 
    signatureAlgorithm: Crypto.ECDSA_Secp256k1)
    keyList.add(
        publicKey,
        hashAlgorithm: Crypto.SHA3_256,
        weight: 0.5
    )
    let signatureSet = [
    Crypto.KeyListSignature(
        keyIndex: 0,
        signature:
            "c5fa321c918a598f2abbc1d9f3f890fdbc1db01836e04ab9f93e21f8a13a24495b9b14d7ad6d010bd25e818e46b0667f3aefd05a945ec9bb854d4fb34fd302241c".decodeHex()
    )]

    let signedData = "5c783139457468657265756d205369676e6564204d6573736167653a5c6e3332666f6f".decodeHex()

    keyList.isValid(
    signatureSet: signatureSet, 
    signedData: signedData
    )
}

```

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [March 9, 2021, 10:04pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/4 "2021-03-09T22:04:47Z")

</div>

Thanks for sharing the code!

I’ve had a look and it seems like there’s a bug where Crypto contract asks for “ECDSA\_Secp256k1”, but it’s named “ECDSA\_secp256k1” in the crypto library:

- [flow-go/types.go at c7b677d94db45668d8a425ca1280017c0aebe1db · onflow/flow-go · GitHub](https://github.com/onflow/flow-go/blob/c7b677d94db45668d8a425ca1280017c0aebe1db/crypto/types.go#L24-L24)
- [cadence/crypto.cdc at a94dfb2147191c4e163bfcc8362bb3367101b910 · onflow/cadence · GitHub](https://github.com/onflow/cadence/blob/a94dfb2147191c4e163bfcc8362bb3367101b910/runtime/stdlib/contracts/crypto.cdc#L225-L225)

@tarak.by Do you have any preference where we should fix this?

---

<div class="post-metadata">

**Author:** ![tarak.by](https://avatars.discourse-cdn.com/v4/letter/t/6bbea6/32.png) [@tarak.by](https://forum.flow.com/u/tarak.by)\
**Post date:** [March 9, 2021, 10:29pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/5 "2021-03-09T22:29:48Z")

</div>

Good catch @MatthewW and @bastian. I would suggest we update the FVM code to decouple the strings from Cadence and the crypto library.

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [March 9, 2021, 10:37pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/6 "2021-03-09T22:37:24Z")

</div>

I’ll open a bug report and will fix this.

Still wanted to mention: `isValid` only returns a boolean to indicate if the signatures are valid, so currently (if the bug is fixed) the script will always succeed, because the result is not used. Maybe use `assert` or return it from the script and check the result off-chain.

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [March 9, 2021, 11:07pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/7 "2021-03-09T23:07:48Z")

</div>

I’ve opened [Fix Crypto.ECDSA\_Secp256k1 by turbolent · Pull Request #510 · onflow/flow-go · GitHub](https://github.com/onflow/flow-go/pull/510) to fix this.

@MatthewW Thank you again for reporting this!

---

<div class="post-metadata">

**Author:** ![MatthewW](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@MatthewW](https://forum.flow.com/u/MatthewW)\
**Post date:** [March 9, 2021, 11:10pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/8 "2021-03-09T23:10:31Z")

</div>

Glad to be of service! Thanks for the quick response time.

---

<div class="post-metadata">

**Author:** ![avcd](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/avcd/32/790_2.png) [@avcd](https://forum.flow.com/u/avcd)\
**Post date:** [March 21, 2021, 11:55am UTC](https://forum.flow.com/t/crypto-contract-bug/1264/9 "2021-03-21T11:55:49Z")

</div>

Hi. I ran into the exact same problem today. I am looking to validate signatures with Ethereum addresses in my contract on Flow.  
This information was very helpful.

However I’m still having this issue with the latest version of Flow CLI (v0.15.0).  
How do I solve this? 😂

Currently, this error occurs in the following environments, which makes it difficult to develop and test the functionality I want to achieve. 💦

- Flow CLI v0.15.0 (`flow scripts execute` command)
- Flow CLI v0.15.0 + @onflow/fcl 0.0.68-alpha.13
- Playground

Any advice would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![bastian](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.flow.com/bastian/32/183_2.png) [@bastian](https://forum.flow.com/u/bastian)\
**Post date:** [March 22, 2021, 5:27pm UTC](https://forum.flow.com/t/crypto-contract-bug/1264/10 "2021-03-22T17:27:25Z")

</div>

This fix hasn’t made it into Emulator/CLI and Playground yet, we’re working on the next release
