Researchers have demonstrated an attack that can impersonate a hardware security module (HSM) to forge signatures using RSA cryptography. This attack, however, does not affect cryptocurrencies like Bitcoin or Ethereum, which utilize different cryptographic algorithms. The findings highlight potential vulnerabilities in key protection mechanisms and underscore the ongoing transition to post-quantum cryptography.
The attack, detailed in a preprint paper submitted to the IACR Cryptology ePrint Archive on September 20, was carried out by researchers from UC San Diego and France’s Institute for Research in Computer Science. According to the authors, the demonstration involved impersonating an HSM without needing to extract the private key. This was achieved by disabling the HSM’s FIPS mode, a certified security setting, which allowed it to sign unformatted numbers. The researchers then performed mathematical operations on the resulting signatures after requesting approximately 4 billion signatures using a 1024-bit RSA key.
Understanding the Attack and its Context
Hardware security modules are tamper-resistant devices designed to store private keys securely and perform cryptographic operations on request. They are commonly used by institutional custody providers, such as BitGo, to protect sensitive digital assets. The core principle of RSA cryptography, developed in 1977, relies on the computational difficulty of factoring large prime numbers. Standard RSA signing processes typically employ padding schemes, like PKCS#1 v1.5 or PSS, which are designed to prevent this type of oracle attack where a signing device is tricked into revealing information about the private key.
The researchers claim that their demonstration likely poses no immediate operational threat to most modern RSA deployments. However, they suggest that this finding serves as classical evidence for moving away from RSA during the post-quantum transition. This recommendation aligns with broader industry trends as quantum computers are expected to pose a significant threat to current cryptographic standards.
Broader Implications for Cryptography
While this specific attack targets RSA, other cryptographic algorithms like the Elliptic Curve Digital Signature Algorithm (ECDSA), used by Bitcoin and Ethereum, are also known to be vulnerable to quantum computing. Estimates suggest that quantum computers with 10,000 to 20,000 qubits could potentially run Shor’s algorithm to break ECDSA signatures. In response to these future threats, companies like Google have set deadlines, such as 2029, to migrate their systems to post-quantum cryptography.
This is not the first time RSA cryptography has been the subject of security concerns. In January 2023, Chinese researchers claimed a quantum method that threatened RSA, but experts dismissed that claim. The current demonstration, while using a test key and specific conditions like disabling FIPS mode, serves as a stress test for how keys are guarded and reinforces the importance of cryptographic agility.
The authors’ findings are presented in a preprint, meaning it has not yet undergone formal peer review. However, the demonstration highlights the ongoing need for vigilance and adaptation in the field of cryptography, particularly as the world prepares for the advent of quantum computing.
Broader Context
Source materials place the factual news in this context: Hardware security modules (HSMs) are tamper-resistant devices that store private keys and sign on request, used by institutional custody providers like BitGo.



