Researchers from UC San Diego and France's Institute for Research in Computer Science (INRIA) successfully forged RSA signatures on a 1,024-bit key within a hardware security module (HSM) without extracting the private key. The attack, detailed in a paper submitted to the IACR Cryptology ePrint Archive on September 20, required approximately 4 billion signing requests and 1,380 CPU core-years of computation. By disabling the HSM's FIPS mode to allow signing of unformatted numbers, the team exploited an oracle vulnerability, effectively learning to replicate the device's stamping function through repeated queries.
The findings do not impact Bitcoin or Ethereum, which utilize elliptic-curve digital signature algorithms such as ECDSA rather than RSA. However, the demonstration serves as a stress test for institutional custody providers that rely on HSMs to safeguard keys. The authors note that standard modern RSA deployments use padding schemes like PKCS#1 v1.5 or PSS, which prevent this specific exploitable oracle, suggesting no immediate operational threat to most systems. The research highlights classical evidence supporting the transition away from RSA during the broader post-quantum cryptography migration, distinct from quantum threats to elliptic curves estimated to require 10,000 to 20,000 qubits.
This development underscores the critical importance of configuration hygiene in cryptographic infrastructure, particularly for institutions relying on hardware security modules for asset custody. While the primary blockchains are insulated from this specific RSA vector, the ability to forge signatures without key extraction challenges the assumption that physical isolation alone guarantees integrity. It reveals that logical vulnerabilities, such as disabled FIPS modes or lack of input validation, can bypass hardware protections, necessitating rigorous audits of how custodial devices handle raw versus padded inputs.
The research acts as a catalyst for accelerating the industry-wide shift toward post-quantum cryptography standards. Although the attack is classical, it reinforces the fragility of legacy RSA implementations even before quantum computers become practical threats. For compliance and risk management teams, the takeaway is not panic over current holdings but a renewed focus on migrating away from vulnerable signature schemes and ensuring that any remaining RSA usage strictly adheres to padded formats to eliminate oracle-based exploitation risks.


