Lifestyle
Researchers Forge RSA Signatures From a Hardware Vault Without Extracting the Key: What It Means for Crypto Assets
According to Decrypt, a UC San Diego and INRIA team forged signatures for a 1,024-bit RSA key inside a hardware security module without extracting the key. This article covers the key points, what is affected, and why Bitcoin and Ethereum signatures fall outside the paper's scope.
About 7 min read

This article draws mainly on a single Decrypt report, with background on Privacy Pass from Cloudflare's official blog. The research findings described below are the claims of the researchers and organisations involved, as reported by those sources.
What happened
According to Decrypt, researchers from UC San Diego and France's INRIA impersonated a hardware security module (HSM, a tamper-resistant device that stores private keys and signs on request) and forged an RSA signature for a 1,024-bit key without the key ever leaving the device. The team detailed the result in a paper submitted to the IACR Cryptology ePrint Archive on September 20. The paper is a preprint, meaning it has not yet been formally peer-reviewed and published.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
Decrypt also points out that the demonstration came with important caveats: the researchers turned off the HSM's FIPS mode (a certified security configuration) so that it would sign unformatted numbers, and they used their own test key. According to the report, the process required roughly 4 billion (about 2^32) signing requests and 1,380 CPU core-years of computation.
Notably, according to Decrypt, the authors write that RSA's security is generally understood to rest on the difficulty of factoring large numbers, but breaking RSA has never been proven equivalent to factoring, and the team did not factor any numbers. In other words, this is not "RSA broken mathematically" but an abuse of the signing service itself under a specific configuration.
Are crypto asset holders affected?
According to Decrypt, Bitcoin uses the ECDSA elliptic-curve digital signature algorithm, and its curve also supports Schnorr signatures; Ethereum and most larger blockchains use similar methods. The paper's claims cover only RSA, so Decrypt states plainly that this is not a break of Bitcoin or Ethereum.
Still, the episode is relevant to how assets are custodied. Decrypt cites BitGo as saying institutional custodians use HSMs so that keys never exist outside the device. This research shows that even if a key never leaves the device, the signing capability itself can still be abused if the device is willing to sign arbitrary, unformatted data. For general readers, the takeaway is that "keeping the key well hidden" and "configuring the signing service properly" matter equally.
| Item | This research | Most modern deployments / major blockchains |
|---|---|---|
| Signature algorithm | RSA (1,024-bit test key) | Bitcoin, Ethereum and others use elliptic-curve signatures such as ECDSA (per Decrypt) |
| Padding | HSM configured to sign unformatted numbers | Standard RSA signatures apply PKCS#1 v1.5 or PSS padding (per Decrypt) |
| FIPS mode | Researchers turned off this certified security setting | Not applicable or depends on the deployment |
| Immediate threat as assessed by authors | Signatures can be forged under specific conditions | Likely no immediate operational threat (authors, as cited by Decrypt) |
Which systems deserve closer attention
According to Decrypt, padded RSA signatures do not create an exploitable "oracle", meaning a device that will sign whatever raw input it is given, much like a vault that stamps any blank paper slid under its door. Some systems, however, deliberately offer this kind of signing capability. RSA-based blind signatures let a server sign something without seeing its contents, and one variant of Privacy Pass works exactly this way.
Cloudflare says on its official blog that it began supporting Privacy Pass in 2017, and that Apple uses a version of Privacy Pass in its Private Access Tokens system, letting users prove they passed a check (such as a CAPTCHA) without revealing their identity. Cloudflare also says the related work helped shape standards such as RSA Blind Signatures (RFC 9474). The Decrypt report does not say these systems have been broken; it only notes that blind signatures are a design type that warrants particular attention.
Blind signatures also have roots in cryptocurrency history: according to Decrypt, cryptographer David Chaum was already using the technique when he founded DigiCash in 1989.
The bigger issue: the post-quantum transition
According to Decrypt, the authors describe the result as "classical" (non-quantum) evidence for moving away from RSA during the post-quantum transition, meaning the shift to cryptography that can withstand quantum computers. Decrypt also notes that "RSA broken" headlines are not new: in January 2023, Chinese researchers claimed a quantum method threatening RSA but only factored a 48-bit number, and experts dismissed it. This time the demonstration used a real 1,024-bit key, but with the major caveat of an enormous number of signing requests.
For Bitcoin, according to Decrypt, the real quantum issue lies with elliptic-curve signatures: Caltech researchers estimated in late March that 10,000 to 20,000 qubits may be enough to run Shor's algorithm in a way that threatens such signatures. Decrypt also reports that Google has set 2029 as its deadline for migrating its own systems to post-quantum cryptography.
Frequently asked questions
Does this mean Bitcoin or Ethereum has been broken?
No. According to Decrypt, Bitcoin and Ethereum use elliptic-curve signatures such as ECDSA, while the paper's claims cover only RSA.
Did the researchers steal the key?
According to Decrypt, no. The researchers forged signatures without the key ever leaving the hardware security module, and they used their own test key.
Is RSA used by ordinary websites or services in immediate danger?
According to Decrypt, the authors say the attack likely poses no immediate operational threat to most modern RSA deployments, because standard practice applies padding such as PKCS#1 v1.5 or PSS. However, the paper is still a preprint.
Why did the research turn off FIPS mode?
According to Decrypt, the researchers turned off FIPS mode so the device would sign unformatted numbers, which was one of the key conditions that made the demonstration work.
How does this relate to the quantum computing threat?
According to Decrypt, this is not a quantum attack, but the authors see it as classical evidence for moving away from RSA during the post-quantum transition. For Bitcoin, the quantum issue mainly concerns elliptic-curve signatures.
As an ordinary user, what do I need to do?
Current reports do not indicate that ordinary users need to take immediate action. A practical approach is to watch for official announcements from your custodian or wallet provider on post-quantum migration and signing configuration, and to rely on the original sources.
Browse the latest news in this topic
Lifestyle
Brazil's Petrobras tests Cardano blockchain to track claims about cleaner jet fuel and diesel
According to CoinDesk, Brazil's state-owned energy company Petrobras is testing the Cardano blockchain in two research projects: one to stop the same emissions cut from sustainable aviation fuel being counted twice, the other to record the history of its partly renewable Diesel R. Both are still research work, with no timeline for wider use.
Lifestyle
Cboe and S&P Dow Jones Indices extend their S&P 500 options deal to 2051 and leave the door open to tokenized options
According to CoinDesk, exchange operator Cboe and index provider S&P Dow Jones Indices have extended Cboe's exclusive right to offer S&P 500 options by 25 years, to 2051. The deal says they may explore blockchain-based 'tokenized' options, but no product, timeline or details were announced. Here is what that means and what it does not.
Lifestyle
SEC Charges Two Groups of Entities Allegedly Behind Crypto Frauds Using WhatsApp and "AI Trading" Claims
On September 29, 2026, the US SEC charged two groups of entities, Cryptoaiml and TSAI, alleging they defrauded hundreds of individual investors, many in the US. The SEC says they falsely claimed to be SEC-regulated and used AI trading signals and bots as bait in schemes totaling at least $15 million. Here is what the SEC alleges and the warning signs readers can watch for.
Lifestyle
Ethereum's Glamsterdam upgrade will go live on the Sepolia test network on October 6; no mainnet date yet
The Ethereum Foundation says its Glamsterdam upgrade, which changes how blocks are built and how fees are counted, is scheduled for the Sepolia test network on October 6, 2026. Test-network node operators and app developers need to prepare. No mainnet date is set, and the Foundation says ordinary users and ETH holders need not act.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family