It was found that no special check against "all bytes same" public keys in OpenSSL crypto.
Thus, due to the recent zeroing of the configuration key, a vulnerability has opened up.
Just now we have used this issue to yet another time update config contract storage - bytes of public key are replaced with
82b17caadb303d53c3286c06a6e1affc517d1bc1d3ef2e4489d18b873f5d7cd1 - sha256 hash of
Not a valid curve point phrase. This means that the vulnerability is closed and no one can use the configuration key.
We thank everyone who participated in the TON bug bounty! This is an example of a bug that gets a top reward.