Brief
Researchers from the University of California, San Diego, and INRIA in France forged RSA signatures within a hardware security module without removing the keys from the device. This type of device is used by custodians to protect encryption keys. The related paper was submitted on September 20th to IACR Cryptology ePrint Archive.
However, cryptocurrency holders need not panic. This is not a vulnerability in Bitcoin or Ethereum. Bitcoin uses the elliptic curve digital signature algorithm, which is also known as ECDSA. (This curve also supports Schnorr signatures.) Ethereum and most large blockchain networks also use similar solutions. What this article discusses is Rivest-Shamir-Adleman cryptography, which is RSA, a different signature scheme.
Nevertheless, this result is still a stress test of how keys are protected. According to the practices of institutional hosting service providers such as BitGo, a hardware security module (HSM) is a tamper-proof device used by companies to protect keys, ensuring that the keys never leave the device. In this case, the keys never left the device, yet researchers were still able to forge signatures.
Researchers turned off the FIPS mode of the hardware security module – a certified security setting – which causes the device to sign unformatted data, and they used their own prepared test keys for this process.
They had the device sign approximately 4 billion numbers that they selected, and then performed mathematical analyses on these results. You can think of it as a vault that is never opened, but they would slip blank papers through the crack in the door to stamp them. With enough requests, it could learn to create this stamp by itself.
What is a signature?
Every time you confirm a transaction, your wallet signs it with your private key. This digital signature serves as proof that the key holder has approved the transaction, and that the message has not been tampered with during transmission.
RSA is a method for constructing such proofs, proposed by Ron Rivest, Leonard Adleman, and Adi Shamir in 1977. The 'S' in the name comes from Shamir.
The core idea of RSA is that it is easy to multiply two large prime numbers together, but it is extremely difficult to reverse this process—i.e., to factorize the result back into its prime factors. The author writes that the security of RSA is generally understood to be based on this difficulty, however, it has never been proven that cracking RSA is completely equivalent to factoring prime numbers. This team did not actually factorize anything.
Who will be affected?
Standard RSA signatures use padding – a step of disruption and formatting that is performed before mathematical operations, such as PKCS #1 v1.5 or PSS – and signatures with padding do not produce predictable or exploitable predicators. The author indicates that this attack is unlikely to pose an immediate operational threat to most modern RSA deployments. This paper is currently still in preprint form.
However, some systems deliberately provide such oracles. Blind signatures based on RSA allow servers to sign without seeing the content, which is also how a certain variant of Privacy Pass works. Cloudflare indicates that Apple uses a version of Privacy Pass that allows users to prove they have passed verification after undergoing checks similar to those in CAPTCHA, without having to expose their identity.
Blind signatures also have a history in the field of cryptography. Cryptographer David Chaum used this technology when he founded DigiCash in 1989.
The greater threat remains quantum computing.
There are precedents for headlines like “RSA has been cracked.” In January 2023, Chinese researchers claimed that a quantum method would pose a threat to RSA, but they only managed to break down a 48-digit number, which was later dismissed by experts. This time, the demonstration indeed targeted a 1,024-bit key, although it came with a footnote as large as that of a predictor.
The authors refer to their findings as classic evidence in support of a gradual transition away from RSA during the post-quantum era, that is, moving towards encryption schemes that can withstand quantum computers.
For Bitcoin, the quantum problem lies in elliptic curve signatures. At the end of March, researchers from Caltech estimated that 10,000 to 20,000 qubits – the quantum version of bits – might be sufficient to run the Shor algorithm, which could threaten such signatures.
Google has set 2029 as the deadline for completing the migration of its systems to post-quantum cryptography.











