Invest1 publisher2 min readPublished
Researchers forge RSA signatures from a hardware security module by making it sign 4 billion raw numbers
UC San Diego and INRIA researchers forged RSA signatures on a 1,024-bit key inside a hardware security module after about 4 billion signing requests. The key stayed inside the device throughout, so for custodians the exposure is in signing settings, starting with the FIPS mode the researchers switched off.
The Investor · Invest desk

What happened
- Bitcoin and Ethereum sign transactions with elliptic-curve schemes such as ECDSA, and the paper's claims cover RSA only.
- Standard RSA signing pads each message first, with PKCS#1 v1.5 or PSS, and padded signatures do not create the oracle the attack relies on.
- The authors say the attack likely poses no immediate operational threat to most modern RSA deployments.
- The paper is a preprint, submitted to the IACR Cryptology ePrint Archive on September 20.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Custodians that hold RSA keys in hardware modules now have to verify that FIPS mode stays on and padding is enforced, since tamper resistance alone did not stop these forgeries.
- exposure Services built on RSA blind signatures, such as one variant of Privacy Pass, hand out the signing oracle on purpose, so they sit closer to this attack than a padded custody deployment does.
- constraint Bitcoin and Ethereum custodians have no RSA migration to fund on this paper's account; their post-quantum planning still turns on elliptic curves, where Caltech put the threshold at 10,000 to 20,000 qubits.
- precedent The authors present the result as classical evidence for leaving RSA during the post-quantum transition, giving RSA holders a reason to retire those keys that does not depend on quantum hardware arriving.
The forgery's cost comes in two units. The compute was 1,380 CPU core-years [5], about 12.1 million core-hours at 8,760 hours a year [1], spent doing math on the device's answers [6]. The requests numbered 2^32, or 4,294,967,296 signatures on numbers the researchers chose [2]. The attackers' machines ran the math, and the module holding the key answered every request [1].
The promise custodians make is about where the key lives. According to BitGo, institutional providers use these modules so that keys never exist outside the device [7], and in this experiment the key stayed put [1]. The weak point was what the device would agree to sign [3]. The researchers also used a test key of their own [3], so no production key in a live custody system was involved.
I think the paper adds lines to a custodian's configuration review and leaves the hardware budget where it was. That budget follows migration timelines. Google, for example, has set 2029 as its deadline to move its own systems to post-quantum cryptography [12]. Decrypt's account does not say whether the module logged or throttled the roughly 4 billion requests [5]. In my view request volume belongs in the review beside the FIPS setting. An attack that needs 2^32 answers only works if the device gives all of them [2]. The counter-case is that 4.3 billion queries and 12.1 million core-hours keep this a laboratory result that no operator needs to budget for [1][2].
Review of the preprint could narrow the result [13]. A follow-up could also reach the same oracle with padding switched on. That would put ordinary deployments in range and show the configuration argument to be too narrow. Claims that RSA is broken have a record. In January 2023, Chinese researchers claimed a quantum method that threatened RSA, yet they had factored only a 48-bit number [14]. This team worked on a real 1,024-bit key and factored nothing [1][15].
What to watch
- Whether review of the ePrint preprint confirms the 2^32-request, 1,380 core-year result or narrows it.
- Any follow-up that reaches the same signing oracle with PKCS#1 v1.5 or PSS padding enabled, or with FIPS mode left on.
- Statements from operators of RSA blind-signature services such as Privacy Pass on how many signing requests they answer and whether they cap them.