Researchers forge RSA signatures inside a hardware security module
Academics tricked a tamper-resistant key vault into signing forged RSA signatures without extracting the key, though the attack does not affect Bitcoin or Ethereum.
Key points
- Researchers at UC San Diego and France's INRIA forged RSA signatures on a 1,024-bit key held inside a hardware security module.
- The attack required roughly 2^32 signing requests, about 4 billion, and 1,380 CPU core-years.
- Bitcoin and Ethereum use elliptic-curve signatures such as ECDSA, not RSA, so the paper's claims do not cover them.
- The researchers disabled the module's FIPS mode and used a test key of their own.
- The authors say the attack likely poses no immediate threat to most modern RSA deployments, which use padding.
Researchers at UC San Diego and France's INRIA forged RSA signatures on a 1,024-bit key held inside a hardware security module, without extracting the key, Decrypt reports. The paper was submitted to the IACR Cryptology ePrint Archive on September 20 and describes impersonating a tamper-resistant device that stores private keys and signs on request.
The result is a stress test of how keys are guarded rather than a break of Bitcoin or Ethereum. Bitcoin signs transactions with the elliptic curve digital signature algorithm, or ECDSA, and its curve also supports Schnorr signatures. Ethereum and most larger blockchains use the same approach, while the paper concerns RSA, a different signature scheme.
Institutional custody providers use hardware security modules so that keys never exist outside the device, according to BitGo. In this case the key never left the module and the researchers still produced forged signatures. They switched off the module's FIPS mode, a certified security setting, so it would sign unformatted numbers, and they used a test key of their own.
Vault tricked without key
The method involved asking the box to sign roughly 4 billion numbers of their choosing, then doing maths on the answers. Decrypt compares it to a vault that never opens but stamps any blank paper slid under the door: ask enough times and you can learn to make the stamp yourself. The work needed about 2^32 signing requests and 1,380 CPU core-years.
RSA was created in 1977 by Ron Rivest, Leonard Adleman and Adi Shamir. Its security is generally understood to rest on the difficulty of factoring the product of two large primes, though breaking RSA has never been proven equivalent to factoring. This team never factored anything, and standard RSA signing applies padding such as PKCS#1 v1.5 or PSS, which does not create the exploitable oracle.
The authors say the attack likely poses no immediate operational threat to most modern RSA deployments, and the paper is a preprint. Some systems expose the oracle deliberately: RSA-based blind signatures let a server sign something without seeing it, which is how one variant of Privacy Pass works. Cloudflare says Apple uses a version of Privacy Pass so users can prove they passed a check without revealing who they are.
Why crypto is unaffected
The authors call their result classical evidence for moving away from RSA during the post-quantum transition. For Bitcoin, the quantum question concerns elliptic-curve signatures; Caltech researchers estimated at the end of March that 10,000 to 20,000 qubits could be enough to run Shor's algorithm. Google has set 2029 as its deadline to migrate its own systems to post-quantum cryptography.