NewsCryptoResearchers Forge RSA Signatures on a Hardware Security Module Without Extracting the Key

Researchers Forge RSA Signatures on a Hardware Security Module Without Extracting the Key

Author: CryptoNewsNet·

Key Takeaways

  • •Researchers from the University of California San Diego and INRIA forged RSA signatures for a 1,024-bit key held inside a hardware security module without ever extracting the private key.
  • •The attack consumed roughly 4 billion attacker-chosen signing queries and about 1,380 CPU core-years of computation, and worked only because the module's FIPS mode was disabled so it would sign raw, unpadded numbers.
  • •The result does not affect Bitcoin or Ethereum, as both use elliptic-curve signature schemes such as ECDSA and Schnorr rather than RSA, and modern RSA deployments with padding face no immediate operational threat.
  • •The demonstration used a 1,024-bit key, below the 2,048-bit minimum that NIST guidance sets for new RSA keys, and the paper remains a preprint awaiting formal peer review.
  • •The authors describe the result as classical evidence for moving away from RSA during the post-quantum transition, for which NIST finalized its first standards in August 2024.
Researchers Forge RSA Signatures on a Hardware Security Module Without Extracting the Key

Researchers at the University of California San Diego and France's INRIA have forged RSA signatures on a 1,024-bit key stored inside a hardware security module (HSM) — the kind of tamper-resistant device institutional custodians use to guard cryptographic keys — without ever extracting the key.

The team detailed the technique in a paper submitted to the IACR (International Association for Cryptologic Research) Cryptology ePrint Archive on September 20. Carrying out the attack required roughly 2^32 signing requests — about 4 billion — and approximately 1,380 CPU core-years of computation. The authors note that the method likely poses no immediate threat to most modern RSA deployments, which rely on padding.

The result is not a break of Bitcoin or Ethereum. Bitcoin signs transactions with the elliptic curve digital signature algorithm (ECDSA), and its curve also supports Schnorr signatures. Ethereum and most other major blockchains use the same elliptic-curve approach. The research targets RSA — Rivest-Shamir-Adleman cryptography — a different signature scheme entirely.

The researchers demonstrated the technique against a hardware security module, a tamper-resistant device that stores private keys and signs data on request. To enable the attack, they disabled the module's FIPS mode — a configuration validated under the U.S. government's Federal Information Processing Standards for cryptographic modules — so that it would sign raw, unformatted numbers, and they supplied their own test key. They then asked the device to sign roughly 4 billion numbers of their choosing and applied mathematical analysis to the responses to construct forged signatures. Cryptographers call such a queryable target an oracle — a system that answers attacker-chosen inputs and whose responses can conceal exploitable patterns. In other words, the result does not show a certified configuration being defeated; it required that configuration to be switched off first.

The setup resembles a vault that never opens but stamps any blank paper slid under the door: request enough stamps, and you can learn to reproduce the stamp yourself.

The finding is a stress test of how keys are guarded in practice. According to BitGo, institutional custody providers use hardware security modules precisely so that private keys never exist outside the device. In this demonstration, the key never left the module — yet signatures were forged anyway.

What a digital signature does

Every time a user confirms a transaction, the wallet signs it with the holder's private key. That digital signature proves the key holder approved the transaction and that no one altered the message along the way.

RSA, devised in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir — the "S" in the acronym — is one way of constructing that proof. Its core idea is that multiplying two enormous prime numbers is easy, while splitting the product back apart — a task known as factoring — is brutally hard. The authors write that RSA's security is generally understood to rest on that difficulty, though breaking RSA has never been proven equivalent to factoring. Notably, the team never factored anything.

Who is affected

Standard RSA signing applies padding — a scrambling and formatting step, such as PKCS#1 v1.5 or PSS, that runs before the mathematics — and padded signatures do not create the exploitable oracle. Key length adds another layer of distance: the demonstration used a 1,024-bit key, while current U.S. standards guidance (NIST) treats 2,048 bits as the minimum for new RSA keys. The authors say the attack likely poses no immediate operational threat to most modern RSA deployments. The paper remains a preprint, with its claims still to run the gauntlet of formal peer review.

Some systems deliberately expose such an oracle. RSA-based blind signatures — a technique specified in an Internet Engineering Task Force standard — allow a server to sign a message without ever seeing it, which is how one variant of Privacy Pass works. According to Cloudflare, Apple uses a version of Privacy Pass so users can prove they passed a check, such as a CAPTCHA, without revealing who they are. Blind signatures also have deep roots in cryptographic history: David Chaum employed the technique when he founded DigiCash in 1989.

The bigger threat is still quantum

"RSA is broken" headlines have a track record. In January 2023, Chinese researchers claimed a quantum method that threatened RSA but had factored only a 48-bit number, and experts dismissed the claim. This time, the demonstration involves an actual 1,024-bit key — albeit with an asterisk the size of the oracle.

The authors describe their result as classical evidence for moving away from RSA during the post-quantum transition — the shift to encryption designed to withstand quantum computers. That transition already has concrete milestones: U.S. standards body NIST finalized its first post-quantum cryptography standards in August 2024, giving vendors and operators a common target for the swap.

For Bitcoin, the quantum question concerns elliptic-curve signatures. Caltech researchers estimated at the end of March that 10,000 to 20,000 qubits — the quantum analogue of bits — could be enough to run Shor's algorithm, the method that threatens these signatures. Google, for its part, has set 2029 as the deadline to finish migrating its own systems to post-quantum cryptography.

This report was originally published by Decrypt: RSA attack without stealing key: what it means for crypto.