================================================================
  UltrafastSecp256k1 -- Industrial Self-Audit Report
================================================================

Library:    UltrafastSecp256k1 v3.4.0
Git Hash:   c8a08445
Framework:  Audit Framework v2.0.0
Timestamp:  2026-03-23T13:55:16
OS:         Linux
Arch:       x86-64
Compiler:   Clang 19.1.7
Build:      Release

----------------------------------------------------------------
  [0] Library Selftest (core KAT)          PASS  (232 ms)
----------------------------------------------------------------

================================================================
  Section 1/8: Mathematical Invariants (Fp, Zn, Group Laws)
================================================================
  [ 1] SEC2 v2.0 curve constant oracle               PASS  (0 ms)
  [ 2] Post-op invariant monitor (on-curve/normalized) PASS  (50 ms)
  [ 3] Field Fp deep audit (add/mul/inv/sqrt/batch)  PASS  (208 ms)
  [ 4] Scalar Zn deep audit (mod/GLV/edge/inv)       PASS  (32 ms)
  [ 5] Point ops deep audit (Jac/affine/sigs)        PASS  (891 ms)
  [ 6] Field & scalar arithmetic                     PASS  (1 ms)
  [ 7] Arithmetic correctness                        PASS  (1 ms)
  [ 8] Scalar multiplication                         PASS  (80 ms)
  [ 9] Exhaustive algebraic verification             PASS  (13 ms)
  [10] Comprehensive 500+ suite                      PASS  (22 ms)
  [11] ECC property-based invariants                 PASS  (2 ms)
  [12] Affine batch addition                         PASS  (200 ms)
  [13] Carry chain stress (limb boundary)            PASS  (0 ms)
  [14] FieldElement52 (5x52) vs 4x64                 PASS  (0 ms)
  [15] FieldElement26 (10x26) vs 4x64                PASS  (0 ms)
  -------- Section Result: 15/15 passed (1501 ms)

================================================================
  Section 2/8: Constant-Time & Side-Channel Analysis
================================================================
  [16] CT deep audit (masks/cmov/cswap/timing)       PASS  (70 ms)
  [17] Constant-time layer                           PASS  (1 ms)
  [18] FAST == CT equivalence                        PASS  (9 ms)
  [19] Side-channel dudect (smoke)                   PASS  (26 ms)
  [20] Formal CT verification (ctgrind/MSAN)         PASS  (1 ms)
  [21] CT scalar_mul vs fast (diagnostic)            PASS  (3 ms)
  -------- Section Result: 6/6 passed (109 ms)

================================================================
  Section 3/8: Differential & Cross-Library Testing
================================================================
  [22] Differential correctness                      PASS  (181 ms)
  [23] Fiat-Crypto reference vectors                 PASS  (0 ms)
  [24] Fiat-Crypto direct linkage (100%% parity)     PASS  (0 ms)
  [25] Cross-platform KAT                            PASS  (0 ms)
  -------- Section Result: 4/4 passed (182 ms)

================================================================
  Section 4/8: Standard Test Vectors (BIP-340, RFC-6979, BIP-32)
================================================================
  [26] BIP-340 official vectors                      PASS  (0 ms)
  [27] BIP-340 strict encoding (non-canonical)       PASS  (0 ms)
  [28] BIP-32 official vectors TV1-5                 PASS  (1 ms)
  [29] RFC 6979 ECDSA vectors                        PASS  (0 ms)
  [30] FROST reference KAT vectors                   PASS  (12 ms)
  [31] MuSig2 BIP-327 reference vectors              PASS  (4 ms)
  [32] Wycheproof ECDSA secp256k1 vectors            PASS  (2 ms)
  [33] Wycheproof ECDH secp256k1 vectors             PASS  (1 ms)
  [34] KAT: ECDH/WIF/P2PKH/P2WPKH/P2TR/hash/arith    PASS  (1 ms)
  -------- Section Result: 9/9 passed (21 ms)

================================================================
  Section 5/8: Fuzzing & Adversarial Attack Resilience
================================================================
  [35] Adversarial fuzz (malform/edge)               PASS  (173 ms)
  [36] Parser fuzz (DER/Schnorr/Pubkey)              PASS  (4252 ms)
  [37] Address/BIP32/FFI boundary fuzz               PASS  (1143 ms)
  [38] Fault injection simulation                    PASS  (57 ms)
  [39] Adversarial protocol & FFI hostile-caller     PASS  (24 ms)
  [40] ECIES regression + C ABI prefix enforce       PASS  (1087 ms)
  -------- Section Result: 6/6 passed (6736 ms)

================================================================
  Section 6/8: Protocol Security (ECDSA, Schnorr, MuSig2, FROST)
================================================================
  [41] ECDSA + Schnorr                               PASS  (0 ms)
  [42] BIP-32 HD derivation                          PASS  (0 ms)
  [43] BIP-39 mnemonic seed phrases                  PASS  (7 ms)
  [44] MuSig2                                        PASS  (1 ms)
  [45] ECDH + recovery + taproot                     PASS  (1 ms)
  [46] v4 (Pedersen/FROST/etc)                       PASS  (2 ms)
  [47] Coins layer                                   PASS  (0 ms)
  [48] MuSig2 + FROST protocol suite                 PASS  (92 ms)
  [49] MuSig2 + FROST advanced/adversar              PASS  (40 ms)
  [50] Integration (ECDH/batch/cross-proto)          PASS  (667 ms)
  [51] Batch verify weight randomness audit          PASS  (1 ms)
  [52] ZK proofs (knowledge/DLEQ/Bulletproof range)  PASS  (817 ms)
  [53] Ethereum signing layer (EIP-191/155/ecrecover) PASS  (1 ms)
  -------- Section Result: 13/13 passed (1629 ms)

================================================================
  Section 7/8: ABI & Memory Safety (zeroization, hardening)
================================================================
  [54] Security hardening (zero/bitflip/nonce)       PASS  (11673 ms)
  [55] Debug invariant assertions                    PASS  (0 ms)
  [56] ABI version gate (compile-time)               PASS  (0 ms)
  [57] Cross-ABI/FFI round-trip (ufsecp C API)       PASS  (5 ms)
  [58] C ABI null/bad-key/bad-sig contract tests     PASS  (0 ms)
  [59] C ABI thread stress (one ctx per thread)      PASS  (21 ms)
  [60] Secure memory erasure (volatile readback)     PASS  (0 ms)
  [61] CT namespace discipline (source-level scan)   PASS  (0 ms)
  [62] RFC 6979 nonce determinism + uniqueness       PASS  (1 ms)
  [63] Public parse path strictness (malformed inputs) PASS  (0 ms)
  [64] GPU C ABI null/invalid-backend/error paths    PASS  (0 ms)
  [65] GPU ABI discovery, lifecycle, ops-if-avail    PASS  (0 ms)
  -------- Section Result: 12/12 passed (11700 ms)

================================================================
  Section 8/8: Performance Validation & Regression
================================================================
  [66] Accelerated hashing                           PASS  (332 ms)
  [67] Multi-scalar & batch verify                   PASS  (1 ms)
  [68] Performance smoke (sign/verify roundtrip)     PASS  (0 ms)
  -------- Section Result: 3/3 passed (333 ms)

================================================================
  AUDIT VERDICT: AUDIT-READY
  TOTAL: 70/70 modules passed  (22.4 s)
  Platform: Linux x86-64 | Clang 19.1.7 | Release
================================================================
