RSA Attack Forges Signatures Inside Hardware Security Module Without Extracting Private Key

57 minute ago 2 sources neutral

Key takeaways:

  • BTC and ETH remain insulated, but HSM interface misconfiguration exposes custody risk beyond key extraction.
  • Custodians must audit raw RSA oracles; padded RSA and ECDSA deployments face minimal immediate threat.
  • Post-quantum migration urgency rises as regulatory scrutiny targets key management and signing controls.

Researchers from UC San Diego and France’s INRIA have demonstrated a practical RSA signature forgery against a hardware security module (HSM), a device widely used by crypto custodians to protect private keys. The team—Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé—submitted their findings to the IACR Cryptology ePrint Archive on September 20, detailing how they impersonated an HSM without ever extracting the private key.

According to the paper, the attack required roughly 2^32 signing requests—more than 4.3 billion queries—and consumed 1,380 CPU core-years over five calendar months. Most of that computation was precomputation; forging an individual chosen signature afterward would take about 180 core-years. By comparison, the researchers estimate that factoring the same 1,024-bit RSA modulus would require approximately 500,000 to 1,000,000 core-years.

The key limitation is that the attack depends on access to a raw, unpadded RSA signing or decryption oracle. The researchers disabled the HSM’s FIPS mode and used their own test key, allowing the device to sign unformatted numbers. Standard RSA signatures using padding schemes such as PKCS#1 v1.5 or RSA-PSS do not expose the necessary oracle, so the authors say the technique likely poses no immediate operational threat to most modern RSA deployments.

Security expert Bruce Schneier noted on September 28 that the underlying algorithm dates back to 2007: “What is new is the implementation.” The result nonetheless adds to concerns about key custody architecture. As BitGo has explained, custodians use HSMs specifically so that keys never leave the device, but this research shows that locking a key in tamper-resistant hardware is insufficient if an attacker can misuse the signing interfaces authorized to call it.

The findings do not break Bitcoin or Ethereum transaction security. Bitcoin uses secp256k1 ECDSA and Schnorr signatures, while Ethereum uses secp256k1 ECDSA; the RSA attack does not apply to those systems. However, the paper strengthens the case for moving away from RSA during the post-quantum transition. It also highlights blind-signature systems, such as Privacy Pass, where raw RSA signing oracles can be deliberately exposed.

Regulatory attention is already moving in this direction. ESMA’s Common Supervisory Action, launched on July 8, focuses on key and storage management, transaction controls and incident response, while EY’s 2026 survey indicates that digital asset security and key-signing procedures have become more important in custodian selection.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.