A Clever RSA Attack Fooled a Hardware Vault—Here's What It Means for Crypto
Researchers from UC San Diego and France's INRIA demonstrated a method to forge RSA signatures generated by a hardware security module (HSM) for a 1,024-bit key without extracting the private key. The attack required about 2^32 signing queries (roughly four billion) and an estimated 1,380 CPU core-years, and the team detailed their paper in an IACR Cryptology ePrint Archive submission on September 20.

Why It Matters
The result shows that a tamper-resistant device can be impersonated to produce valid RSA signatures even when its private key never leaves the module, exposing a practical oracle-style weakness in unpadded RSA deployments. Although it does not affect elliptic-curve schemes used by major cryptocurrencies and likely poses limited immediate risk to padded RSA systems, the demonstration underscores operational risks around key-guarding and informs the broader move away from RSA in a post-quantum transition.
Key Facts
- Researchers: UC San Diego and France's INRIA
- Paper submission date: September 20 (IACR Cryptology ePrint Archive)
- Key type attacked: RSA, 1,024-bit key
- Signing queries required: Approximately 2^32 (about 4 billion)
- Compute cost: About 1,380 CPU core-years
A team led by UC San Diego, collaborating with France's INRIA, reported a technique that forges RSA signatures produced by a hardware security module (HSM) without ever extracting the device's private key. The authors submitted a paper describing the attack to the IACR Cryptology ePrint Archive on September 20. Their demonstration targeted a 1,024-bit RSA key and relied on using the HSM as a signing oracle rather than breaking the underlying factoring problem.
To carry out the attack the researchers disabled the HSM's FIPS mode so the device would sign raw, unformatted numbers, and they used a test key of their own. They then requested roughly 4 billion tailored signing operations and performed offline computation on the results; the total estimated computational effort for the attack was about 1,380 CPU core-years. The authors emphasize that they did not factor the RSA modulus during the attack.
The paper's scope is limited to RSA and does not impact the elliptic-curve signature schemes used by major cryptocurrencies: Bitcoin uses ECDSA (and supports Schnorr), and Ethereum uses similar elliptic-curve signatures. The researchers note standard RSA signing routines that apply padding schemes such as PKCS#1 v1.5 or PSS do not produce the oracle the attack exploits, so most modern RSA deployments that use proper padding are likely not immediately endangered.
The attack also highlights operational considerations where systems intentionally provide a signing oracle. Blind-signature constructions, which underpin some privacy-preserving protocols like variants of Privacy Pass, intentionally allow a server to sign messages it cannot read; the paper points out these designs could be affected. The authors frame their result as additional classical evidence supporting migration away from RSA during the post-quantum cryptography transition. The broader quantum-threat discussion remains distinct: prior claims in 2023 about a quantum method threatening RSA were dismissed after factoring only a 48-bit number, while estimates cited in the discussion suggest thousands of qubits would be needed to run quantum attacks on elliptic-curve schemes. Major companies, including Google, have set migration timelines—Google targets completion of its post-quantum migration by 2029.
Keep Reading

Nvidia Built a Kill Switch for AI Agents Because They Keep Getting Out

After AI Agent Hacked Its Government, Australia Calls Altman and Amodei to Testify

Anthropic's Claude Sonnet 5.5 Is Out, Beats Opus 5.5 at Coding for Half the Price
