NewsCryptoResearchers Forge RSA Signatures Inside Hardware Security Module Without Extracting the Key

Researchers Forge RSA Signatures Inside Hardware Security Module Without Extracting the Key

Author: Decrypt·

Key Takeaways

  • •Researchers from UC San Diego and INRIA forged RSA signatures for a 1,024-bit key while it remained inside a hardware security module, detailing the attack in a paper submitted to the IACR Cryptology ePrint Archive on September 20.
  • •The demonstration involved switching off the module's FIPS mode, using a test key, sending about 2^32 (roughly 4 billion) chosen signing requests, and an estimated 1,380 CPU core-years of computation.
  • •The attack does not affect Bitcoin or Ethereum because those networks use elliptic-curve signatures such as ECDSA and Schnorr rather than RSA.
  • •Standard RSA padding schemes like PKCS#1 v1.5 and PSS prevent the exploitable oracle, so the authors say the attack likely poses no immediate operational threat to most modern RSA deployments.
  • •The authors describe the result as classical evidence for moving away from RSA during the post-quantum transition, a shift Google aims to complete for its own systems by 2029.
Researchers Forge RSA Signatures Inside Hardware Security Module Without Extracting the Key

Researchers at the University of California San Diego and France's INRIA have forged RSA signatures on a 1,024-bit key stored inside a hardware security module, the tamper-resistant device institutional custodians rely on to guard crypto keys—without ever extracting the key itself.

The researchers effectively impersonated a hardware security module, a device that stores private keys and signs on request, coaxing valid signatures out of it while the key stayed inside. They detailed the attack in a paper submitted to the IACR Cryptology ePrint Archive on September 20.

For crypto holders, the finding is not a break of Bitcoin or Ethereum. Bitcoin signs transactions with the elliptic curve digital signature algorithm, or ECDSA, and its curve also supports Schnorr signatures. Ethereum and most other major blockchains use elliptic-curve signatures as well. This paper concerns Rivest-Shamir-Adleman cryptography, or RSA, a different signature scheme.

Still, the result is a stress test of how keys get guarded. Institutional custody providers, according to BitGo, use hardware security modules—tamper-resistant boxes designed so that keys never exist outside the hardware and outsiders can only request signatures. Here, the key never left the device, and the researchers forged signatures anyway.

They did switch off the module's FIPS mode, a certified security setting, so it would sign unformatted numbers, and they used a test key of their own. They then asked the box to sign roughly 4 billion numbers of their choosing—about 2^32 signing requests—before doing the math on the answers. The computation totaled an estimated 1,380 CPU core-years. Think of a vault that never opens but stamps any blank paper you slide under the door: ask enough times, and you can learn to make the stamp yourself.

What's a signature?

Every time a user confirms a transaction, their wallet signs it with a private key. That digital signature proves the key holder approved the transaction and that nobody altered the message in transit, making signatures foundational to every transfer of value on a blockchain.

RSA is one way of building that proof. It was created in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, the "S" in the name. The key idea is that multiplying two enormous prime numbers is easy, but splitting the result back apart—a process called factoring—is brutally hard. The authors write that RSA's security is generally understood to rest on that difficulty, though breaking RSA has never been proven equivalent to factoring. This team never factored anything.

Who is affected

Standard RSA signing applies padding—a scrambling and formatting step, such as PKCS#1 v1.5 or PSS, that runs before the underlying math—and padded signatures do not create the exploitable oracle. In practice, the attack works only against a device configured to sign raw, unformatted numbers. The reported exposure therefore depends on the signing interface and its configuration, not simply on whether a key is stored in an HSM. The authors say it likely poses no immediate operational threat to most modern RSA deployments. The paper is a preprint.

Some systems hand out the oracle on purpose RSA-based blind signatures let a server sign something without seeing it, which is how one variant of Privacy Pass works. Cloudflare says Apple uses a version of Privacy Pass so users can prove they passed a check, such as a CAPTCHA, without revealing who they are.

Blind signatures have crypto roots. Cryptographer David Chaum used the technique when he founded DigiCash in 1989.

The bigger threat is still quantum

"RSA is broken" headlines have a track record. In January 2023, Chinese researchers claimed a quantum method that threatened RSA but had only factored a 48-bit number, and experts dismissed the claim. This time, the demonstration involves an actual 1,024-bit key—with an asterisk the size of the oracle.

The authors describe their result as classical evidence for moving away from RSA during the post-quantum transition, the shift to encryption built to survive quantum computers.

For Bitcoin, the quantum question concerns elliptic-curve signatures. Caltech researchers estimated at the end of March that 10,000 to 20,000 qubits—the quantum version of bits—could be enough to run Shor's algorithm, the method that threatens those signatures.

Google has set 2029 as its deadline to finish migrating its own systems to post-quantum cryptography.