Invest1 publisher2 min readPublished
Forging a 1024-bit RSA signature through an HSM costs under 0.3% of factoring the key
UC San Diego and Inria researchers forged a 1024-bit RSA signature through an HSM in 1,380 core-years, against at least 500,000 to factor the key. The attack only works with raw, unpadded signing access, so how exposed a custodian is depends on how its HSM is configured.
The Investor · Invest desk

What happened
- The team sent the HSM 2^32 signing requests, a little over 4.3 billion queries, to build the forgery.
- Most of the work is a one-time precomputation, after which each further chosen-signature forgery needs around 180 core-years.
- According to Decrypt, the researchers switched off the HSM's certified FIPS mode and used a test key of their own.
- The paper says raw signing access exists in HSM APIs and in RSA blind-signature systems such as the one RFC 9474 describes.
- Bitcoin and Ethereum sign transactions with secp256k1 ECDSA, plus Schnorr on Bitcoin, so the demonstrated attack does not reach them.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Repeating the demonstration means keeping about 3,300 cores busy for five months, a compute bill the attacker pays offline after the queries are collected.
- constraint Per-client rate limits do little for a blind-signature issuer with a large fleet: at one token a minute, 2.3 billion devices reach the paper's 2^43 queries in about 2.3 days.
- decision Longer RSA keys do not restore the margin, since with a signing oracle even 4096-bit RSA falls below 128-bit security, according to the researchers.
- exposure Custodians now face a specific, checkable question, which RSA keys accept raw requests, in selection and supervisory reviews that EY and ESMA say already weigh signing procedures.
On the researchers' own figures the oracle route is roughly 360 to 725 times cheaper than factoring. 1,380 core-years goes into 500,000 about 362 times and into 1,000,000 about 725 times [1]. The mathematics is old, and the algorithm dates to 2007 [6]. "What is new is the implementation," Bruce Schneier said on September 28 [7]. The paper, IACR ePrint 2026/2131, is by Laura Shea, Miro Haller, Adam Suhl and Nadia Heninger of UC San Diego, with Emmanuel Thomé of Inria [16].
The part closest to custody is timing. According to the paper, temporary access to a raw signing oracle can eventually give an attacker the ability to forge signatures offline [17]. An intruder in an authorized signing system does not have to stay. The queries are collected during the breach, and the forging runs later on the attacker's own machines. A Cryptopolitan report on September 20 linked about $2 million drained from Fetch.ai and NuNet to compromised signing authorities, though in that case someone obtained the key [18].
If production HSMs holding keys of value turn out to accept raw RSA requests, the exposure is wide and every RSA key behind an API needs checking. A narrower outcome is that the practical targets are blind-signature issuers of the RFC 9474 kind, where the server signs a blinded message without seeing the original [9]. In that case the cost falls on token services and custodians mostly watch. Should neither show up in practice, the paper's lasting effect is on security estimates, felt slowly in key-size and algorithm choices.
I'd put the most weight on the second outcome. Standard PKCS#1 v1.5 and RSA-PSS signing do not open the raw path, and the Cryptopolitan report says the attack cannot be considered practical against properly implemented RSA [15]. The case against that view is that the paper names HSM APIs themselves as a place raw access occurs [9]. The report does not say how often that option is enabled in production.
The spending this justifies is small. A custodian needs an inventory of every RSA key held in an HSM and the mechanisms each one accepts. Buying new hardware does nothing against an attack in which the key never left the device [1]. The view that custodians are mostly bystanders is wrong if an audit finds a production custody HSM answering raw RSA requests on a key that authorizes client transfers.
What to watch
- Whether HSM vendors respond to ePrint 2026/2131 by disabling or deprecating raw RSA signing mechanisms by default.
- What ESMA's Common Supervisory Action, launched July 8, reports about transaction controls and key management at custodians.
- Whether operators of RFC 9474 blind-signature services publish query limits or change RSA parameters after the paper.