Researchers forge 1024-bit RSA signature without extracting private key

แหล่งที่มา Cryptopolitan

A team of researchers from UC San Diego showed that a 1024-bit RSA signature can be forged by sending multiple queries to a hardware security module (HSM). In this case, the private key was never extracted from the device.

This result implies yet another form of risk for crypto custodians: keeping the key inside tamper-proof hardware is not sufficient if the attacker hacks the systems that have been authorized to use it.

Forging a signature the key never signed

In IACR ePrint 2026/2131, Laura Shea, Miro Haller, Adam Suhl and Nadia Heninger of UC San Diego, with Emmanuel Thomé of Inria, describe how temporary access to a raw RSA signing oracle can eventually give an attacker the ability to forge signatures offline.

The attack process consisted of 2^32 basic signing requests: this counts to a little more than 4.3 billion queries and results in 1,380 CPU core-years used of computing time over a period of five calendar months.

In comparison with the work done, as calculated by the researchers’ project materials, factoring the same 1024-bit RSA modulus would take approximately 500,000-1,000,000 core-years. Most of the work that is conducted is done only once during precomputing; afterwards, forging of a chosen signature should require around 180 core-years.

The algorithm used was invented back in 2007. What has changed is that the team of researchers actually succeeded in conducting a real attack, as noted by Bruce Schneier on September 28:

“What is new is the implementation.” — Bruce Schneier

Why unpadded signing is the whole trick

An essential restriction exists with respect to this type of attack: it requires the availability of a raw unpadded RSA signing or decryption oracle. Standard RSA signatures using PKCS#1 v1.5 or RSA-PSS do not provide this access. Therefore, this attack cannot be considered a practical attack on properly implemented RSA.

As Decrypt noted, the researchers turned off the certified FIPS mode on the HSM and used a test key of their own.

According to the paper, the occurrence of raw signing access can be seen in HSM APIs and RSA blind-signature systems. The paper then goes on to state that RFC 9474, for instance, explains a scenario where the server signs the blinded message without any access to the original message.

The study uses Apple’s figure of 2.3 billion active devices to show how fast concurrent requests can pile up. At one token per minute, a single device would need about 17 million years to reach 2^43 queries. But if you look at the full figure of 2.3 billion devices, the same number of requests can be made in just about 2.3 days.

Signing interfaces as part of the perimeter

For crypto custodians, locking the private key in a safe does not provide complete safety. The APIs, approval processes, and automated systems that utilize the private key pose their own dangers.

This concern is already reflected in the industry. According to EY’s 2026 survey, security of digital coins, as well as key-signing procedures, have become far more significant in the custodian selection process. The Common Supervisory Action of ESMA, launched on July 8, also focus on the scrutiny of key and storage management, transaction controls and incident response.

According to the researchers, RSA with a signature oracle provides 15-30 bits lower security than factoring-based estimates for typical 1024-4096-bit keys. In this model, 4096-bit RSA does not even provide the security of 128-bit encryption.

Not a Bitcoin or Ethereum break

The paper is about RSA. Ethereum uses secp256k1 ECDSA, while Bitcoin uses secp256k1 ECDSA and Schnorr signatures, so the demonstrated attack does not apply to their transaction-signing systems.

The larger issue concerning custody risk isn’t something that’s entirely fresh. A Cryptopolitan report on September 20 has indicated how compromised signing authorities have drained around $2 million from Fetch.ai and NuNet. While the case above involved an individual obtaining the key, this report shows that the attacker might gain signing authority without ever obtaining the key.

If you're reading this, you’re already ahead. Stay there with our newsletter.

ข้อจำกัดความรับผิดชอบ: เพื่อการอ้างอิงเท่านั้น ผลการดำเนินงานในอดีตไม่ได้บ่งบอกถึงผลลัพธ์ในอนาคต
placeholder
ข่าวหุ้นวันนี้ ทรัมป์–สีจับตาการค้า บอนด์ยีลด์ทะลุ 5% กดหุ้น–ทอง ขณะที่ Bitcoin หลุด $85K และ SET ยังแกว่งทันทุกกระแสการเงิน สรุปข่าวเด่น Forex หุ้น ทองคำ คริปโตฯ และเศรษฐกิจรอบวัน วิเคราะห์แนวโน้มตลาดด้วยข้อมูลเชิงลึก อ่านง่าย เข้าใจไว อัปเดตล่าสุดที่นี่
ผู้เขียน  Mitrade
9 เดือน 24 วัน พฤหัส
ทันทุกกระแสการเงิน สรุปข่าวเด่น Forex หุ้น ทองคำ คริปโตฯ และเศรษฐกิจรอบวัน วิเคราะห์แนวโน้มตลาดด้วยข้อมูลเชิงลึก อ่านง่าย เข้าใจไว อัปเดตล่าสุดที่นี่
placeholder
WTI ยังคงปรับตัวขึ้นเล็กน้อยเหนือระดับ $92.00 ท่ามกลางความวิตกกังวลเกี่ยวกับตะวันออกกลางWest Texas Intermediate (WTI) – ราคาน้ำมันดิบอ้างอิงของสหรัฐฯ – พยายามใช้ประโยชน์จากการเปิดตลาดที่ปรับตัวขึ้นเล็กน้อยในวันจันทร์ ขณะที่เทรดเดอร์เลือกที่จะรอความคืบหน้าเพิ่มเติมเกี่ยวกับวิกฤตตะวันออกกลางก่อนวางเดิมพันใหม่ อย่างไรก็ตาม WTI ยังคงมีแนวโน้มขาขึ้นตลอดช่วงเซสชั่นเอเชีย และปัจจุบันเคลื่อนไห
ผู้เขียน  FXStreet
9 เดือน 28 วัน จันทร์
West Texas Intermediate (WTI) – ราคาน้ำมันดิบอ้างอิงของสหรัฐฯ – พยายามใช้ประโยชน์จากการเปิดตลาดที่ปรับตัวขึ้นเล็กน้อยในวันจันทร์ ขณะที่เทรดเดอร์เลือกที่จะรอความคืบหน้าเพิ่มเติมเกี่ยวกับวิกฤตตะวันออกกลางก่อนวางเดิมพันใหม่ อย่างไรก็ตาม WTI ยังคงมีแนวโน้มขาขึ้นตลอดช่วงเซสชั่นเอเชีย และปัจจุบันเคลื่อนไห
placeholder
ทองคำดีดตัวจากระดับ 4,110 ดอลลาร์ ขณะที่การร่วงลงของราคาน้ำมันช่วยคลายแรงกดดันด้านเงินเฟ้อราคาทองคำ (XAU/USD) ปรับตัวเพิ่มขึ้นอย่างแข็งแกร่งกว่า 1.30% ในวันอังคาร แม้เจ้าหน้าที่ธนาคารกลางสหรัฐฯ (เฟด) จะแสดงความเห็นไปในทาง hawkish หลังแตะระดับต่ำสุดในรอบหลายสัปดาห์ใกล้ $4,110 เมื่อวันจันทร์ คู่ XAU/USD ซื้อขายอยู่ที่ $4,170 หลังดีดตัวขึ้นจากระดับต่ำสุดรายวันที่ $4,113.
ผู้เขียน  FXStreet
9 เดือน 30 วัน พุธ
ราคาทองคำ (XAU/USD) ปรับตัวเพิ่มขึ้นอย่างแข็งแกร่งกว่า 1.30% ในวันอังคาร แม้เจ้าหน้าที่ธนาคารกลางสหรัฐฯ (เฟด) จะแสดงความเห็นไปในทาง hawkish หลังแตะระดับต่ำสุดในรอบหลายสัปดาห์ใกล้ $4,110 เมื่อวันจันทร์ คู่ XAU/USD ซื้อขายอยู่ที่ $4,170 หลังดีดตัวขึ้นจากระดับต่ำสุดรายวันที่ $4,113.
placeholder
ราคาโลหะเงินถอยลง ขณะที่อัตราผลตอบแทนพันธบัตรสหรัฐที่ปรับตัวสูงขึ้นและความตึงเครียดในช่องแคบฮอร์มุซหนุนดอลลาร์สหรัฐโลหะเงิน (XAG/USD) ปรับตัวลดลงในวันอังคาร และเคลื่อนไหวอยู่ที่ประมาณ $60.75 ณ เวลาที่รายงานข่าวนี้ ลดลง 0.38% ในวันนี้
ผู้เขียน  FXStreet
9 เดือน 30 วัน พุธ
โลหะเงิน (XAG/USD) ปรับตัวลดลงในวันอังคาร และเคลื่อนไหวอยู่ที่ประมาณ $60.75 ณ เวลาที่รายงานข่าวนี้ ลดลง 0.38% ในวันนี้
placeholder
ทองคำปรับตัวลดลงใกล้ระดับ $4,150 เนื่องจากอัตราผลตอบแทนพันธบัตรกระทรวงการคลังสหรัฐฯ และราคาน้ำมันที่สูงขึ้น มีน้ำหนักมากกว่าอัตราเงินเฟ้อ PCE ที่ชะลอตัวลงในช่วงเช้าของตลาดลงทุนเอเชียวันพฤหัสบดี ราคาทองคำ (XAUUSD) ร่วงลงมาใกล้ $4,150 โดยถูกกดดันจากอัตราผลตอบแทนพันธบัตรรัฐบาลสหรัฐฯ ที่อยู่ในระดับสูง เทรดเดอร์รอข้อมูลการจ้างงานของสหรัฐฯ ประจำเดือนกันยายนเพื่อหาแรงผลักดันใหม่ ซึ่งจะมีการประกาศในช่วงต่อไปของวันศุกร์
ผู้เขียน  FXStreet
1 ชั่วโมงที่แล้ว
ในช่วงเช้าของตลาดลงทุนเอเชียวันพฤหัสบดี ราคาทองคำ (XAUUSD) ร่วงลงมาใกล้ $4,150 โดยถูกกดดันจากอัตราผลตอบแทนพันธบัตรรัฐบาลสหรัฐฯ ที่อยู่ในระดับสูง เทรดเดอร์รอข้อมูลการจ้างงานของสหรัฐฯ ประจำเดือนกันยายนเพื่อหาแรงผลักดันใหม่ ซึ่งจะมีการประกาศในช่วงต่อไปของวันศุกร์
goTop
quote