see https://github.com/bitcoin-core/secp256k1/pull/791 The solution should be to not implement multiplication on points marked as secret.