BNB $761.39 -0.45%
XRP $1.50 +0.99%
ETH $2,691.09 +1.61%
BTC $83,834.40 +0.84%
BNB $761.39 -0.45%
XRP $1.50 +0.99%
ETH $2,691.09 +1.61%
BTC $83,834.40 +0.84%
BREAKING
Bitcoin News

Researchers Successfully Forge RSA Signatures, Compromising Hardware Security Modules

UC San Diego and French Researchers Forge RSA Signatures on 1,024-Bit Hardware Module
UC San Diego and French Researchers Forge RSA Signatures on 1,024-Bit Hardware Module

Community Trust ScoreVerified

83%
Real
Verified35 votes
Updated 3 hours ago

Researchers cracked something that wasn’t supposed to crack. A team from UC San Diego and France’s Institute for Research in Computer Science managed to impersonate a hardware security module — without ever pulling its private key out.

Their paper landed in the IACR Cryptology ePrint Archive on September 20. The work zeroes in on RSA cryptography — Rivest-Shamir-Adleman, the old workhorse of public-key encryption — not on the elliptic curve digital signature algorithm that Bitcoin and Ethereum run on. So crypto holders aren’t the immediate audience here. But the broader security world probably should be paying attention.

How the Attack Actually Worked

The trick started with a surprisingly simple move: they switched off the hardware security module’s FIPS mode. FIPS is a certified security setting, basically a compliance lock that tells the device to behave itself. Kill that mode, and the module will sign unformatted numbers — raw, unpadded integers that a properly configured device would normally refuse to touch.

Advertisement

From there, the researchers used a controlled test key and requested signatures for roughly 4 billion numbers. Four billion. That’s not a typo. By collecting enough of those signatures, they could mathematically work backward and forge new ones — without ever learning the underlying private key.

The analogy in the paper is pretty vivid. Think of a vault that never opens but stamps any blank paper slid under its door. Slide enough papers under, study enough stamps, and eventually you can replicate the stamp yourself. The vault stays locked. You don’t need it anymore.

RSA’s core security assumption is that factoring two very large prime numbers is computationally brutal. But this attack didn’t involve factoring at all. It’s a different angle entirely — what’s called a signing oracle attack. Standard RSA implementations use padding, a scrambling step baked into the signing process that basically closes this door. The attack doesn’t work against properly padded RSA. But not every system uses padding correctly, and that’s kind of the point.

The team demonstrated the technique with a 1,024-bit key. That’s a meaningful jump from the last headline-grabbing RSA result — in January 2023, Chinese researchers claimed to have factored a 48-bit number, which is orders of magnitude smaller. A 1,024-bit demonstration is a different tier of result, even if the conditions required to pull it off are strict.

What This Means for Crypto and Post-Quantum Security

Bitcoin and Ethereum aren’t affected. Full stop. Both networks rely on elliptic curve cryptography, which is a separate mathematical universe from RSA. The researchers were explicit about that distinction, and it’s worth repeating because the word “cryptography attack” tends to make crypto markets nervous even when the relevance is basically zero.

That said, the paper raises questions that matter for the broader digital security stack. RSA still shows up in older enterprise systems, certificate authorities, and certain authentication protocols. Any of those running without proper padding — or with misconfigured FIPS settings — probably need a closer look.

There’s also a specific carve-out worth noting: some systems intentionally use RSA-based blind signatures, which let transactions happen without exposing the underlying data. Apple’s Privacy Pass is one example. The research touches on how those implementations interact with the kind of oracle the researchers exploited, which is a more nuanced conversation than a simple “RSA is broken” take.

The quantum angle looms over all of this. The paper pushes on the idea that RSA may get shakier during the post-quantum transition — the messy window when organizations are migrating away from classical encryption but haven’t fully landed on quantum-resistant alternatives. Google has targeted 2029 for migrating its own systems to post-quantum encryption standards. That deadline isn’t far off, and research like this probably adds pressure to move faster rather than slower.

On the Bitcoin side specifically, the threat model is different. Research from Caltech put the quantum risk to elliptic-curve signatures at somewhere around 10,000 to 20,000 qubits — the point where Shor’s algorithm could theoretically break those signatures. No quantum computer is close to that today, but the runway isn’t infinite.

Practical Limits of the Attack

It’s worth being clear about what this attack isn’t. It’s not a practical exploit someone runs against live RSA infrastructure tomorrow. The conditions required are specific: physical or logical access to the hardware security module, the ability to disable FIPS mode, and the patience to collect signatures across billions of requests. That’s not nothing. In most real-world deployments, those conditions don’t exist.

But the research matters as a stress test. It maps a real boundary in how RSA key protection works — or doesn’t — when implementation assumptions break down. And with the post-quantum clock ticking, the industry’s tolerance for “technically possible but unlikely” attack surfaces is probably shrinking fast.

The 1,024-bit demonstration stands as the clearest proof yet of what a signing oracle can do in the right hands.

Frequently Asked Questions

Did the researchers actually steal a private key from the hardware security module?

No. The team from UC San Diego and France’s Institute for Research in Computer Science forged signatures without extracting the private key, by collecting roughly 4 billion signed responses from the module after disabling its FIPS mode.

Does this RSA attack put Bitcoin or Ethereum at risk?

No. Bitcoin and Ethereum use elliptic curve digital signature algorithm (ECDSA), which is a separate cryptographic system not affected by this RSA-focused research.

Why It Matters

This research highlights significant vulnerabilities in RSA cryptography, an established standard in security protocols, which could have implications for various sectors relying on this encryption method. As the crypto landscape continues to evolve, the findings may prompt a reevaluation of security measures across industries, particularly in financial systems and blockchain technologies that depend on strong cryptographic foundations. The ability to impersonate hardware security modules without extracting private keys raises concerns about the robustness of current encryption standards and could accelerate the shift toward more secure alternatives.

Community Trust IndexHigh Confidence
83%
Real
Real83%17%Fake
35 community signals

Sakamoto Nashi

Nashi Sakamoto is a dedicated crypto journalist from the Virgin Islands who brings expert analysis on Bitcoin, Ethereum, DeFi protocols, and the broader digital asset ecosystem to The Currency Analytics.

Advertisement

Related Stories