RSA2026-09-28 21:16:03Researchers Forge RSA Signatures From a Hardware Security Module Without Extracting the KeyResearchers from the University of California San Diego and France’s Institute for Research in Computer Science said they were able to impersonate a hardware security module, or HSM, without ever extracting the private key stored inside it. Their paper, submitted to the IACR Cryptology ePrint Archive on September 20, focuses on RSA rather than the signature systems used by Bitcoin and Ethereum. That distinction matters: Bitcoin relies on ECDSA, with support for Schnorr signatures on the same curve, while Ethereum and most major blockchains use similar elliptic-curve schemes. The result still raises questions about how institutional key storage is protected. According to BitGo, custody providers use HSMs so keys never exist outside the device. In this case, the key stayed inside the box, yet the researchers still produced forged signatures after disabling the module’s FIPS mode and querying it to sign roughly 4 billion chosen numbers with a test key they controlled. The authors said standard padded RSA signatures such as PKCS#1 v1.5 or PSS are not exposed to the same oracle, and they added that the attack likely poses no immediate operational threat to most modern RSA deployments. The paper also places fresh attention on the longer-term push away from RSA as the industry prepares for post-quantum cryptography.200
Ethereum2026-09-27 10:46:46Vitalik outlines post-Hegota Ethereum plans as a hybrid blockchain and cryptography architectureVitalik said in a post on X that he was trying to briefly explain the real meaning of Ethereum’s various plans starting from the post-Hegota fork. In his description, Ethereum is no longer just a blockchain. He said it is becoming a hybrid architecture that combines blockchain systems with modern cryptography, a shift he said can enable stronger capabilities. Vitalik also listed several initiatives tied to that direction, including FOCIL, EIP-8288, leaner consensus, state management, formal verification, mempool improvements with privacy features, and longer-term obfuscation technologies. The remarks were cited by ChainCatcher in a market analysis newsflash.250
post-quantum 2026-09-21 16:21:39Flaws Found in China’s Post-Quantum Crypto Candidates, Raising Questions for Bitcoin Security PlanningBitcoin News said in a post on X that China launched a next-generation commercial cryptography program in 2025 to develop and evaluate standards designed to withstand future quantum computers. During a review of candidate algorithms, independent researcher @mjos_crypto said several proposed schemes showed critical weaknesses. The issues cited included publicly reproducible private keys, hash collisions that could be constructed easily, and signature implementations that accepted invalid signatures. The post tied those findings to the broader debate around Bitcoin’s long-term quantum readiness. Bitcoin currently relies on established elliptic curve cryptography, which has been broadly tested and remains part of its security model today. At the same time, the report noted that moving too early to post-quantum systems that have not been tested enough could introduce vulnerabilities before any practical quantum threat arrives. The episode highlights a core tension in crypto security planning: preparing for a future risk without weakening current systems through immature replacements.360
RSA-8962026-09-20 02:38:44RSA-896 cryptography challenge broken with AI assistance, pushing public key record to 896 bitsTechub News reported that the RSA-896 cryptography challenge has been successfully factored with assistance from artificial intelligence, extending the publicly recorded key-length milestone to 896 bits. The update points to AI’s growing ability to speed up work on difficult mathematical problems rather than merely automate routine tasks. It also puts fresh attention on the security assumptions behind existing encryption standards, as advances in computation and tooling can change how long hard problems remain practical to defend against. The report cited Crypto Briefing as the source of the development. No additional technical details, timeline of the factorization process, or parties involved were disclosed in the brief.260
Claude2026-09-15 07:35:10Claude cracks a 370-year-old cipher in 44 minutes and then solves a second Urquhart puzzleClaude Fable 5.1 has been reported to solve a 370-year-old cipher left by 17th-century English scholar Sir Thomas Urquhart, finishing the task in 44 minutes while using 176,000 tokens and without human intervention during the process. The first puzzle, known as the Cyphral Distich and published at the end of Urquhart’s 1653 work Logopandecteision, consists of two lines of 32 numbers each and had resisted attempts by scholars and hobbyists for centuries. According to the report, Claude identified that the key was not an external codebook but the book itself: each number pointed to a numbered petition and then to a word position, with the plaintext recovered by taking first letters. The output read, “O GOD UPHOLD KING CHARLS THE SECOND AND” and “MAKE HIM THE SUPREME RULER OF THIS LAND.” After that, the model applied the same book-as-index logic to Urquhart’s Cyphral Octastich in The Jewel, a longer puzzle built from 285 numbers, and used EEBO-TCP plus self-written Python scripts for layout calibration to reconstruct a full iambic eight-line poem. The report also linked this result to broader AI research work disclosed by Anthropic and comments from Vals AI on rapid iteration across archival tasks.330
Anthropic2026-09-15 03:00:21Claude Fable 5.1 reportedly cracked a 373-year-old Scottish cipher in 44 minutesVals AI said in an official blog post that Anthropic’s Claude Fable 5.1 solved a 373-year-old Scottish cipher in 44 minutes using 176,000 tokens, with no human intervention during the run. The puzzle, known as the Cyphral Distich, was left by Scottish nobleman Thomas Urquhart at the end of his 1653 book Logopandecteision and consists of two lines of 32 numbers each. According to Vals AI, the model found that the key was not an external cipher table or codebook, as many earlier researchers had assumed, but the book itself: each number points to a word position in a matching Proquiritation passage, and the first letters spell out a prayer in support of Charles II. Vals AI also said the same logic helped decode a larger cipher, the Cyphral Octastich, in Urquhart’s 1652 work The Jewel. Still, the firm acknowledged that the result has not been independently reviewed by cipher historians, and the larger Octastich solution still contains unresolved gaps, including nine unreadable letters and a one-page offset after the 159th number.680
Anthropic2026-09-14 05:22:45Fable 5.1 solves a 370-year-old cipher in 44 minutes, with the clue sitting beside the textVals AI researcher Geby Jaff said in an experiment log published on Aug. 31 that Claude Fable 5.1 solved a 370-year-old unsolved cipher in 44 minutes without his intervention. The write-up reached Hacker News’ front page on Sept. 13 and collected more than 600 points. The cipher, known as Cyphral Distich, consists of 64 numbers printed at the end of Sir Thomas Urquhart’s Logopandecteision and had been treated as an open problem since 1899. Jaff said earlier attempts focused on external cipher systems, while Fable 5.1 identified a simpler route: the key was the book itself, specifically the 32 Proquiritations printed immediately before the cipher. Using each number as a word-position index and taking the first letter of the target word, the model produced a royalist message in support of Charles II. Jaff also said the model applied a similar method to the larger Cyphral Octastich in The Jewel, though nine letters remain unresolved and would require a physical copy or the 1983 Jack Lyall edition to verify fully.750
Vitalik Buter2026-09-06 13:32:24Vitalik: SNARK Likely to Achieve Single-Digit Computation Overhead by End of DecadeEthereum co-founder Vitalik Buterin shared an optimistic non-consensus view on the long-term development of cryptography. He assessed that SNARK, FHE, and iO protocols have a 33% probability of keeping total cost within 1+ε times the base computational cost for general real-world computation, and a 60% probability of keeping the cost multiplier below 10x when combining energy and amortized costs. He predicted that at least one of these goals will likely be achieved before the end of this decade, most likely SNARK reaching single-digit computational overhead. He noted that in specialized hash functions and some large language model reasoning scenarios, this level has already been reached.900