A critical vulnerability has been discovered in the PuTTY tools, affecting versions 0.68 to 0.80, which can compromise private keys using the NIST P521 curve. The vulnerability allows an attacker to recover the private key and forge signatures, but only affects keys used with PuTTY or Pageant. The issue is due to a biased nonce generation method, which has been fixed by switching to the RFC 6979 technique. Users with affected keys are advised to revoke and replace them.