Researchers Forge RSA Signatures From a Hardware Security Module Without Extracting the Key

Researchers Forge RSA Signatures From a Hardware Security Module Without Extracting the Key

N
News Editor
2026-09-28 21:16:03
Researchers from the University of California San Diego and France’s Institute for Research in Computer Science said they were able to impersonate a hardware security module, or HSM, without ever extracting the private key stored inside it. Their paper, submitted to the IACR Cryptology ePrint Archive on September 20, focuses on RSA rather than the signature systems used by Bitcoin and Ethereum. That distinction matters: Bitcoin relies on ECDSA, with support for Schnorr signatures on the same curve, while Ethereum and most major blockchains use similar elliptic-curve schemes. The result still raises questions about how institutional key storage is protected. According to BitGo, custody providers use HSMs so keys never exist outside the device. In this case, the key stayed inside the box, yet the researchers still produced forged signatures after disabling the module’s FIPS mode and querying it to sign roughly 4 billion chosen numbers with a test key they controlled. The authors said standard padded RSA signatures such as PKCS#1 v1.5 or PSS are not exposed to the same oracle, and they added that the attack likely poses no immediate operational threat to most modern RSA deployments. The paper also places fresh attention on the longer-term push away from RSA as the industry prepares for post-quantum cryptography.

Researchers at the University of California San Diego and France’s Institute for Research in Computer Science said they managed to impersonate a hardware security module, or HSM, without ever extracting the private key from the device. They described the method in a paper submitted to the IACR Cryptology ePrint Archive on September 20.

The finding does not mean Bitcoin or Ethereum have been broken. Bitcoin uses the elliptic curve digital signature algorithm, ECDSA, and its curve also supports Schnorr signatures. Ethereum and most large blockchains use the same family of signature systems. The paper is about RSA, a different cryptographic signature scheme.

Even so, the result puts key protection under pressure. BitGo has said institutional custody providers use HSMs so private keys never exist outside the device. In this case, the key never left the hardware module, and the researchers still forged signatures.

The team disabled the HSM’s FIPS mode, a certified security setting, so the device would sign unformatted numbers. They also used a test key of their own.

From there, they asked the box to sign roughly 4 billion numbers they selected, then analyzed the responses mathematically. The article compares it to a vault that never opens but stamps any blank sheet pushed under the door. With enough requests, someone may learn how to reproduce the stamp without access to the vault itself.

What the signature does

Each time a user confirms a transaction, a wallet signs it with a private key. That digital signature shows the key holder approved the action and that the message was not altered in transit.

RSA is one way to build that proof. It was introduced in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, whose surnames form the acronym.

The basic idea behind RSA is that multiplying two very large prime numbers is easy, while splitting the product back into its factors is extremely hard. The paper’s authors wrote that RSA security is generally understood to rest on that difficulty, although breaking RSA has never been formally proven equivalent to factoring. In this work, the researchers did not factor anything.

Who is affected

Standard RSA signing usually applies padding before the core math, using schemes such as PKCS#1 v1.5 or PSS. Those padded signatures do not create the oracle used in this attack. The authors said the method likely poses no immediate operational threat to most modern RSA deployments. The paper is a preprint.

Some systems intentionally expose that kind of oracle. RSA-based blind signatures let a server sign something without seeing the content, which is how one version of Privacy Pass works. Cloudflare has said Apple uses a version of Privacy Pass so users can prove they passed a check, such as a CAPTCHA, without revealing who they are.

Blind signatures also have deep roots in crypto. Cryptographer David Chaum used the technique when he founded DigiCash in 1989.

The larger risk remains quantum computing

Headlines claiming that RSA is broken have appeared before. In January 2023, Chinese researchers claimed a quantum method that threatened RSA, but they had only factored a 48-bit number, and experts rejected the claim. This time, the demonstration used an actual 1,024-bit key, though it came with a major condition: the attack depends on access to a very large oracle.

The authors described the result as classical evidence for moving away from RSA during the post-quantum transition, meaning the shift toward cryptography designed to withstand quantum computers.

For Bitcoin, the quantum issue centers on elliptic-curve signatures. Researchers at Caltech estimated at the end of March that 10,000 to 20,000 qubits could be enough to run Shor’s algorithm, the method that threatens those signatures.

Google has set 2029 as its deadline to complete the migration of its own systems to post-quantum cryptography.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.