The Go implementation of the P-256 elliptic curve had a small bug due to a misplaced carry bit affecting less than 0.00000003% of field subtraction operations. We show how to build a full practical key recovery attack on top of it, capable of targeting JSON Web Encryption
We should really work in the projective plane, so as to have a point “at infinity” which resolves this issue and serves as the identity element for the group.