UCSD2026-09-28 21:24:36UCSD-led team simulates HSM operations without extracting keysA research team led by the University of California, San Diego said it was able to simulate the operation of a hardware security module, or HSM, without extracting the cryptographic keys stored inside the device. The method targeted a weakness in the RSA signing process rather than breaking into the module to pull out secret material. According to the report, the attack worked by sending a large number of carefully crafted signing requests to the HSM and then examining side-channel signals such as response timing. Using that information, the researchers were ultimately able to forge valid digital signatures. The finding points to a potential security risk for crypto exchanges, custody providers, and blockchain networks that rely on HSMs for key management and transaction signing. The researchers said the result shows that even physically isolated hardware can still face remote attack risk, and that stronger defensive measures may be needed across the industry. The item was cited by Techub and attributed to Decrypt.20
RSA2026-09-28 21:16:03Researchers Forge RSA Signatures From a Hardware Security Module Without Extracting the KeyResearchers from the University of California San Diego and France’s Institute for Research in Computer Science said they were able to impersonate a hardware security module, or HSM, without ever extracting the private key stored inside it. Their paper, submitted to the IACR Cryptology ePrint Archive on September 20, focuses on RSA rather than the signature systems used by Bitcoin and Ethereum. That distinction matters: Bitcoin relies on ECDSA, with support for Schnorr signatures on the same curve, while Ethereum and most major blockchains use similar elliptic-curve schemes. The result still raises questions about how institutional key storage is protected. According to BitGo, custody providers use HSMs so keys never exist outside the device. In this case, the key stayed inside the box, yet the researchers still produced forged signatures after disabling the module’s FIPS mode and querying it to sign roughly 4 billion chosen numbers with a test key they controlled. The authors said standard padded RSA signatures such as PKCS#1 v1.5 or PSS are not exposed to the same oracle, and they added that the attack likely poses no immediate operational threat to most modern RSA deployments. The paper also places fresh attention on the longer-term push away from RSA as the industry prepares for post-quantum cryptography.20