Researchers at the University of California San Diego and France’s Institute for Research in Computer Science said they managed to impersonate a hardware security module, or HSM, without ever extracting the private key from the device. They described the method in a paper submitted to the IACR Cryptology ePrint Archive on September 20.
The finding does not mean Bitcoin or Ethereum have been broken. Bitcoin uses the elliptic curve digital signature algorithm, ECDSA, and its curve also supports Schnorr signatures. Ethereum and most large blockchains use the same family of signature systems. The paper is about RSA, a different cryptographic signature scheme.
Even so, the result puts key protection under pressure. BitGo has said institutional custody providers use HSMs so private keys never exist outside the device. In this case, the key never left the hardware module, and the researchers still forged signatures.
The team disabled the HSM’s FIPS mode, a certified security setting, so the device would sign unformatted numbers. They also used a test key of their own.
From there, they asked the box to sign roughly 4 billion numbers they selected, then analyzed the responses mathematically. The article compares it to a vault that never opens but stamps any blank sheet pushed under the door. With enough requests, someone may learn how to reproduce the stamp without access to the vault itself.
What the signature does
Each time a user confirms a transaction, a wallet signs it with a private key. That digital signature shows the key holder approved the action and that the message was not altered in transit.
RSA is one way to build that proof. It was introduced in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, whose surnames form the acronym.
The basic idea behind RSA is that multiplying two very large prime numbers is easy, while splitting the product back into its factors is extremely hard. The paper’s authors wrote that RSA security is generally understood to rest on that difficulty, although breaking RSA has never been formally proven equivalent to factoring. In this work, the researchers did not factor anything.
Who is affected
Standard RSA signing usually applies padding before the core math, using schemes such as PKCS#1 v1.5 or PSS. Those padded signatures do not create the oracle used in this attack. The authors said the method likely poses no immediate operational threat to most modern RSA deployments. The paper is a preprint.
Some systems intentionally expose that kind of oracle. RSA-based blind signatures let a server sign something without seeing the content, which is how one version of Privacy Pass works. Cloudflare has said Apple uses a version of Privacy Pass so users can prove they passed a check, such as a CAPTCHA, without revealing who they are.
Blind signatures also have deep roots in crypto. Cryptographer David Chaum used the technique when he founded DigiCash in 1989.
The larger risk remains quantum computing
Headlines claiming that RSA is broken have appeared before. In January 2023, Chinese researchers claimed a quantum method that threatened RSA, but they had only factored a 48-bit number, and experts rejected the claim. This time, the demonstration used an actual 1,024-bit key, though it came with a major condition: the attack depends on access to a very large oracle.
The authors described the result as classical evidence for moving away from RSA during the post-quantum transition, meaning the shift toward cryptography designed to withstand quantum computers.
For Bitcoin, the quantum issue centers on elliptic-curve signatures. Researchers at Caltech estimated at the end of March that 10,000 to 20,000 qubits could be enough to run Shor’s algorithm, the method that threatens those signatures.
Google has set 2029 as its deadline to complete the migration of its own systems to post-quantum cryptography.

