In brief

  • Researchers at UC San Diego and France's INRIA forged RSA signatures on a 1,024-bit key inside a hardware security module, the kind of device custodians use to guard crypto keys, without extracting the key.
  • Bitcoin and Ethereum sign transactions with elliptic-curve signatures such as ECDSA rather than RSA, and the paper's claims cover RSA only.
  • The attack needed about 2^32 signing requests (roughly 4 billion) and 1,380 CPU core-years, and the authors say it likely poses no immediate threat to most modern RSA deployments, which use padding.

Researchers at UC San Diego and France's Institute for Research in Computer Science impersonated a hardware security module—a tamper-resistant device that stores private keys and signs on request—without ever pulling the key out of it. They detailed the attack in a paper submitted to the IACR Cryptology ePrint Archive on September 20.

But don’t panic, crypto holders. This is not a Bitcoin or Ethereum break. Bitcoin uses an elliptic curve digital signature algorithm, or ECDSA. (Its curve also supports Schnorr signatures.) Ethereum, and most of the bigger blockchains, use the same. This paper is about Rivest-Shamir-Adlemen cryptography, or RSA, a different signature scheme.

Myriad: How high will Bitcoin go? Click to make your prediction.
Myriad: How high will Bitcoin go? Click to make your prediction.

Still, the result is a stress test of how keys get guarded. Institutional custody providers, per BitGo, use a hardware security module—a tamper-resistant box that companies use to guard keys— so that keys never exist outside the device. Here the key never left the device, and the researchers forged signatures anyway.

They did switch off the hardware security module’s FIPS mode, a certified security setting, so it would sign unformatted numbers, and they used a test key of their own.

They asked the box to sign roughly 4 billion numbers of their choosing, then did math on the answers. Think of a vault that never opens but stamps any blank paper you slide under the door. Ask enough times, and you can learn to make the stamp yourself.

What's a signature?

Every time you confirm a transaction, your wallet signs it with your private key. That digital signature is the proof that the key holder approved it, and that nobody altered the message on the way.

RSA is one way of building that proof, created in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, the "S" in the name.

BitcoinBTC · USD

$83,458−3.62%

Sep 21Sep 23Sep 25Sep 27Sep 28

$87.2k$85.7k$84.2k$82.7k

24h HighHigh$84,945

24h LowLow$82,581

VolVol$1.8B

→

Buy Bitcoin with USDT

Powered by Jupiter

Price data by CoinGeckoCoinGeckoMore Bitcoin news and projections →

The key idea of RSA is that multiplying two enormous prime numbers is easy, but splitting the result back apart (called factoring) is brutally hard. The authors write that RSA's security is generally understood to rest on that difficulty, though breaking RSA has never been proven equivalent to factoring. This team never factored anything.

Who is affected

Standard RSA signing applies padding—a scrambling and formatting step, such as PKCS#1 v1.5 or PSS, that runs before the math—and padded signatures don't create the exploitable oracle. The authors say the attack likely poses no immediate operational threat to most modern RSA deployments. The paper is a preprint.

Some systems hand out the oracle on purpose. RSA-based blind signatures let a server sign something without seeing it, which is how one variant of Privacy Pass works. Cloudflare says Apple uses a version of Privacy Pass so users can prove they passed a check, like a CAPTCHA, without revealing who they are.

Blind signatures have crypto roots. Cryptographer David Chaum used the technique when he founded DigiCash in 1989.

The bigger threat is still quantum

"RSA is broken" headlines have a track record. In January 2023, Chinese researchers claimed a quantum method that threatened RSA, but had only factored a 48-bit number, and experts dismissed it. This time the demonstration is an actual 1,024-bit key, with an asterisk the size of the oracle.

The authors call their result classical evidence for moving away from RSA during the post-quantum transition, meaning the shift to encryption built to survive quantum computers.

For Bitcoin, the quantum question is elliptic-curve signatures. Caltech researchers estimated at the end of March that 10,000 to 20,000 qubits—the quantum version of bits—could be enough to run Shor's algorithm, the method that threatens these signatures.

Google has set 2029 as its deadline to finish migrating its own systems to post-quantum cryptography.