Researchers forge 1024-bit RSA signature without extracting private key

Fuente Cryptopolitan

A team of researchers from UC San Diego showed that a 1024-bit RSA signature can be forged by sending multiple queries to a hardware security module (HSM). In this case, the private key was never extracted from the device.

This result implies yet another form of risk for crypto custodians: keeping the key inside tamper-proof hardware is not sufficient if the attacker hacks the systems that have been authorized to use it.

Forging a signature the key never signed

In IACR ePrint 2026/2131, Laura Shea, Miro Haller, Adam Suhl and Nadia Heninger of UC San Diego, with Emmanuel Thomé of Inria, describe how temporary access to a raw RSA signing oracle can eventually give an attacker the ability to forge signatures offline.

The attack process consisted of 2^32 basic signing requests: this counts to a little more than 4.3 billion queries and results in 1,380 CPU core-years used of computing time over a period of five calendar months.

In comparison with the work done, as calculated by the researchers’ project materials, factoring the same 1024-bit RSA modulus would take approximately 500,000-1,000,000 core-years. Most of the work that is conducted is done only once during precomputing; afterwards, forging of a chosen signature should require around 180 core-years.

The algorithm used was invented back in 2007. What has changed is that the team of researchers actually succeeded in conducting a real attack, as noted by Bruce Schneier on September 28:

“What is new is the implementation.” — Bruce Schneier

Why unpadded signing is the whole trick

An essential restriction exists with respect to this type of attack: it requires the availability of a raw unpadded RSA signing or decryption oracle. Standard RSA signatures using PKCS#1 v1.5 or RSA-PSS do not provide this access. Therefore, this attack cannot be considered a practical attack on properly implemented RSA.

As Decrypt noted, the researchers turned off the certified FIPS mode on the HSM and used a test key of their own.

According to the paper, the occurrence of raw signing access can be seen in HSM APIs and RSA blind-signature systems. The paper then goes on to state that RFC 9474, for instance, explains a scenario where the server signs the blinded message without any access to the original message.

The study uses Apple’s figure of 2.3 billion active devices to show how fast concurrent requests can pile up. At one token per minute, a single device would need about 17 million years to reach 2^43 queries. But if you look at the full figure of 2.3 billion devices, the same number of requests can be made in just about 2.3 days.

Signing interfaces as part of the perimeter

For crypto custodians, locking the private key in a safe does not provide complete safety. The APIs, approval processes, and automated systems that utilize the private key pose their own dangers.

This concern is already reflected in the industry. According to EY’s 2026 survey, security of digital coins, as well as key-signing procedures, have become far more significant in the custodian selection process. The Common Supervisory Action of ESMA, launched on July 8, also focus on the scrutiny of key and storage management, transaction controls and incident response.

According to the researchers, RSA with a signature oracle provides 15-30 bits lower security than factoring-based estimates for typical 1024-4096-bit keys. In this model, 4096-bit RSA does not even provide the security of 128-bit encryption.

Not a Bitcoin or Ethereum break

The paper is about RSA. Ethereum uses secp256k1 ECDSA, while Bitcoin uses secp256k1 ECDSA and Schnorr signatures, so the demonstrated attack does not apply to their transaction-signing systems.

The larger issue concerning custody risk isn’t something that’s entirely fresh. A Cryptopolitan report on September 20 has indicated how compromised signing authorities have drained around $2 million from Fetch.ai and NuNet. While the case above involved an individual obtaining the key, this report shows that the attacker might gain signing authority without ever obtaining the key.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Descargo de responsabilidad: Sólo con fines informativos. Rentabilidades pasadas no son indicativas de resultados futuros.
placeholder
El WTI cae cerca de 91.00$ mientras las exportaciones de crudo de Oriente Próximo se recuperanEl petróleo West Texas Intermediate (WTI) ha reducido sus ganancias recientes del día anterior, cotizando alrededor de 91.10$ por barril durante el horario europeo del martes. Los precios del petróleo crudo se han relajado tras un rebote de las exportaciones en septiembre por parte de importantes productores de Oriente Medio.
Autor  FXStreet
14 hace una horas
El petróleo West Texas Intermediate (WTI) ha reducido sus ganancias recientes del día anterior, cotizando alrededor de 91.10$ por barril durante el horario europeo del martes. Los precios del petróleo crudo se han relajado tras un rebote de las exportaciones en septiembre por parte de importantes productores de Oriente Medio.
placeholder
El rendimiento del bono estadounidense a 10 años repunta hasta el 5,236%, máximo desde junio de 2007El bono americano a 10 años se sitúa en el 5,236% al cierre del 28 de septiembre, su nivel más alto desde junio de 2007. El giro restrictivo de la Fed, los datos económicos sólidos y la débil demanda en las subastas explican el movimiento, que presiona a la baja a bolsas, oro y EUR/USD.
Autor  Mitrade Team
16 hace una horas
El bono americano a 10 años se sitúa en el 5,236% al cierre del 28 de septiembre, su nivel más alto desde junio de 2007. El giro restrictivo de la Fed, los datos económicos sólidos y la débil demanda en las subastas explican el movimiento, que presiona a la baja a bolsas, oro y EUR/USD.
placeholder
Oro: La tendencia bajista persiste por debajo de la DMA de 200 – Societe GeneraleLos analistas de Société Générale señalan que el precio del Oro no ha logrado mantener las ganancias por encima de su media móvil de 200 días, reforzando el impulso bajista. Está en curso un retroceso a corto plazo, con una resistencia clave en el máximo de giro reciente cerca de los 4.315$
Autor  FXStreet
El dia de ayer 09: 22
Los analistas de Société Générale señalan que el precio del Oro no ha logrado mantener las ganancias por encima de su media móvil de 200 días, reforzando el impulso bajista. Está en curso un retroceso a corto plazo, con una resistencia clave en el máximo de giro reciente cerca de los 4.315$
placeholder
EUR/USD cae a 1,1377, el euro registra su peor mes desde junio frente al dólarEl EUR/USD cotiza en 1,1377 el 28 de septiembre y acumula una caída del 1,7% en septiembre, su peor mes desde junio. La presión vendedora responde al diferencial de tasas entre la Fed y el BCE, la escalada geopolítica en Oriente Medio y unos datos económicos insuficientes para revertir la tendencia. Los analistas vigilan el soporte de 1,1350 y 1,1324.
Autor  Mitrade Team
El dia de ayer 08: 17
El EUR/USD cotiza en 1,1377 el 28 de septiembre y acumula una caída del 1,7% en septiembre, su peor mes desde junio. La presión vendedora responde al diferencial de tasas entre la Fed y el BCE, la escalada geopolítica en Oriente Medio y unos datos económicos insuficientes para revertir la tendencia. Los analistas vigilan el soporte de 1,1350 y 1,1324.
placeholder
Oro: La tendencia bajista se mantiene por debajo de la resistencia de 4.300 - OCBCLos estrategas de OCBC Sim Moh Siong y Christopher Wong señalan que el precio del Oro sigue bajo presión a corto plazo tras caer brevemente por debajo de 4250 antes de rebotar ligeramente.
Autor  FXStreet
9 Mes 25 Día Vie
Los estrategas de OCBC Sim Moh Siong y Christopher Wong señalan que el precio del Oro sigue bajo presión a corto plazo tras caer brevemente por debajo de 4250 antes de rebotar ligeramente.
goTop
quote