In \packages/agent-mesh/sdks/typescript/src/encryption/x3dh.ts, \�erifyBundle()\ only checks field lengths — it does NOT perform Ed25519 signature verification on the signed prekey.
Additionally, \PreKeyBundle\ schema doesn't include the Ed25519 identity key needed for verification (only has X25519 key).
Fix needed:
- Add \identityKeyEd\ (Ed25519 public key) to PreKeyBundle schema
- Call \�d25519.verify(sig, signedPreKey, identityKeyEd)\ in verifyBundle()
This is a real crypto-binding regression vs the vendored SDK.
Ref: Azure/kars#27 review (blocker #6)
In \packages/agent-mesh/sdks/typescript/src/encryption/x3dh.ts, \�erifyBundle()\ only checks field lengths — it does NOT perform Ed25519 signature verification on the signed prekey.
Additionally, \PreKeyBundle\ schema doesn't include the Ed25519 identity key needed for verification (only has X25519 key).
Fix needed:
This is a real crypto-binding regression vs the vendored SDK.
Ref: Azure/kars#27 review (blocker #6)