Lifestyle

Researchers Forge RSA Signatures From a Hardware Vault Without Extracting the Key: What It Means for Crypto Assets

According to Decrypt, a UC San Diego and INRIA team forged signatures for a 1,024-bit RSA key inside a hardware security module without extracting the key. This article covers the key points, what is affected, and why Bitcoin and Ethereum signatures fall outside the paper's scope.

About 7 min read

Researchers Forge RSA Signatures From a Hardware Vault Without Extracting the Key: What It Means for Crypto Assets
Image: Mokaair (Original editorial artwork)

This article draws mainly on a single Decrypt report, with background on Privacy Pass from Cloudflare's official blog. The research findings described below are the claims of the researchers and organisations involved, as reported by those sources.

What happened

According to Decrypt, researchers from UC San Diego and France's INRIA impersonated a hardware security module (HSM, a tamper-resistant device that stores private keys and signs on request) and forged an RSA signature for a 1,024-bit key without the key ever leaving the device. The team detailed the result in a paper submitted to the IACR Cryptology ePrint Archive on September 20. The paper is a preprint, meaning it has not yet been formally peer-reviewed and published.

Researchers Forge RSA Signatures From a Hardware Vault Without Extracting the Key: What It Means for Crypto Assets
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

Decrypt also points out that the demonstration came with important caveats: the researchers turned off the HSM's FIPS mode (a certified security configuration) so that it would sign unformatted numbers, and they used their own test key. According to the report, the process required roughly 4 billion (about 2^32) signing requests and 1,380 CPU core-years of computation.

Notably, according to Decrypt, the authors write that RSA's security is generally understood to rest on the difficulty of factoring large numbers, but breaking RSA has never been proven equivalent to factoring, and the team did not factor any numbers. In other words, this is not "RSA broken mathematically" but an abuse of the signing service itself under a specific configuration.

Are crypto asset holders affected?

According to Decrypt, Bitcoin uses the ECDSA elliptic-curve digital signature algorithm, and its curve also supports Schnorr signatures; Ethereum and most larger blockchains use similar methods. The paper's claims cover only RSA, so Decrypt states plainly that this is not a break of Bitcoin or Ethereum.

Still, the episode is relevant to how assets are custodied. Decrypt cites BitGo as saying institutional custodians use HSMs so that keys never exist outside the device. This research shows that even if a key never leaves the device, the signing capability itself can still be abused if the device is willing to sign arbitrary, unformatted data. For general readers, the takeaway is that "keeping the key well hidden" and "configuring the signing service properly" matter equally.

Key differences between this RSA attack demonstration and typical deployments (source: Decrypt report)
ItemThis researchMost modern deployments / major blockchains
Signature algorithmRSA (1,024-bit test key)Bitcoin, Ethereum and others use elliptic-curve signatures such as ECDSA (per Decrypt)
PaddingHSM configured to sign unformatted numbersStandard RSA signatures apply PKCS#1 v1.5 or PSS padding (per Decrypt)
FIPS modeResearchers turned off this certified security settingNot applicable or depends on the deployment
Immediate threat as assessed by authorsSignatures can be forged under specific conditionsLikely no immediate operational threat (authors, as cited by Decrypt)

Which systems deserve closer attention

According to Decrypt, padded RSA signatures do not create an exploitable "oracle", meaning a device that will sign whatever raw input it is given, much like a vault that stamps any blank paper slid under its door. Some systems, however, deliberately offer this kind of signing capability. RSA-based blind signatures let a server sign something without seeing its contents, and one variant of Privacy Pass works exactly this way.

Cloudflare says on its official blog that it began supporting Privacy Pass in 2017, and that Apple uses a version of Privacy Pass in its Private Access Tokens system, letting users prove they passed a check (such as a CAPTCHA) without revealing their identity. Cloudflare also says the related work helped shape standards such as RSA Blind Signatures (RFC 9474). The Decrypt report does not say these systems have been broken; it only notes that blind signatures are a design type that warrants particular attention.

Blind signatures also have roots in cryptocurrency history: according to Decrypt, cryptographer David Chaum was already using the technique when he founded DigiCash in 1989.

The bigger issue: the post-quantum transition

According to Decrypt, the authors describe the result as "classical" (non-quantum) evidence for moving away from RSA during the post-quantum transition, meaning the shift to cryptography that can withstand quantum computers. Decrypt also notes that "RSA broken" headlines are not new: in January 2023, Chinese researchers claimed a quantum method threatening RSA but only factored a 48-bit number, and experts dismissed it. This time the demonstration used a real 1,024-bit key, but with the major caveat of an enormous number of signing requests.

For Bitcoin, according to Decrypt, the real quantum issue lies with elliptic-curve signatures: Caltech researchers estimated in late March that 10,000 to 20,000 qubits may be enough to run Shor's algorithm in a way that threatens such signatures. Decrypt also reports that Google has set 2029 as its deadline for migrating its own systems to post-quantum cryptography.

Frequently asked questions

Does this mean Bitcoin or Ethereum has been broken?

No. According to Decrypt, Bitcoin and Ethereum use elliptic-curve signatures such as ECDSA, while the paper's claims cover only RSA.

Did the researchers steal the key?

According to Decrypt, no. The researchers forged signatures without the key ever leaving the hardware security module, and they used their own test key.

Is RSA used by ordinary websites or services in immediate danger?

According to Decrypt, the authors say the attack likely poses no immediate operational threat to most modern RSA deployments, because standard practice applies padding such as PKCS#1 v1.5 or PSS. However, the paper is still a preprint.

Why did the research turn off FIPS mode?

According to Decrypt, the researchers turned off FIPS mode so the device would sign unformatted numbers, which was one of the key conditions that made the demonstration work.

How does this relate to the quantum computing threat?

According to Decrypt, this is not a quantum attack, but the authors see it as classical evidence for moving away from RSA during the post-quantum transition. For Bitcoin, the quantum issue mainly concerns elliptic-curve signatures.

As an ordinary user, what do I need to do?

Current reports do not indicate that ordinary users need to take immediate action. A practical approach is to watch for official announcements from your custodian or wallet provider on post-quantum migration and signing configuration, and to rely on the original sources.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle