[…] right now the ecmult_gen uses a random projection for the initial point (secp256k1_gej_rescale). ([…] the rescale currently only happens on randomize– but that is already something that should get fixed independent of anything being done with the inversion).
Originally posted by @gmaxwell in #767 (comment)