2015.08.09 23:26:27 (630490349345992704) from Daniel J. Bernstein, replying to "hannoππππ (@hanno)" (629411466047651840):
No. The buggy code never passed NaCl's pre-release auditing procedures. We've been working on automated verification to help audits. @hanno
2015.08.06 23:59:22 (629411466047651840) from "hannoππππ (@hanno)":
learn that nacl and tweetnacl had a carry-propagation bug in ed25519 code @ bignum talk @BlackHatEvents