Researchers from UC San Diego and France’s INRIA have shown that a hardware security module (HSM) can be coaxed into producing valid RSA signatures for a 1,024-bit key without ever revealing the private key. The demonstration, detailed in a pre-print paper, involved an extensive series of signing queries rather than a direct key extraction.
How the attack works
The team disabled the HSM’s FIPS-approved security mode, allowing the device to sign raw numeric inputs. By submitting approximately 4 billion crafted messages to the module and recording the resulting signatures, they built a mathematical model that enabled them to generate forged signatures on their own. The process consumed an estimated 1,380 CPU core-years of computation.
Scope of impact
The attack targets RSA-based digital signatures, a scheme distinct from the elliptic-curve algorithms (ECDSA and Schnorr) used by Bitcoin, Ethereum and most major blockchains. Consequently, the vulnerability does not affect those networks directly. However, many custodial services—such as institutional crypto custodians—rely on HSMs to protect RSA keys for ancillary functions, including certificate signing and certain privacy-preserving protocols.
Mitigations in current RSA deployments
Standard RSA signing implementations incorporate padding schemes like PKCS#1 v1.5 or RSA-PSS before the mathematical operation. These padding steps prevent the type of oracle the researchers exploited, rendering the attack ineffective against properly padded RSA signatures. Additionally, keeping the HSM’s FIPS mode enabled blocks the ability to sign unformatted numbers, eliminating the attack surface used in the demonstration.
Broader cryptographic considerations
While the attack does not immediately threaten contemporary RSA usage, it serves as a concrete stress test of key-protection mechanisms. The authors argue that the result reinforces the case for transitioning away from RSA as part of the broader post-quantum migration, especially given ongoing research into quantum algorithms that could undermine RSA and elliptic-curve schemes alike. Estimates suggest that a quantum computer with 10,000–20,000 qubits could run Shor’s algorithm against elliptic-curve signatures, prompting industry players such as Google to set migration deadlines around 2029.
Why it matters
The demonstration highlights that even tamper-resistant hardware can leak enough information to recreate cryptographic proofs when security settings are relaxed. For organizations that still depend on RSA for digital signatures, ensuring that HSMs operate in fully compliant modes and employ padding is essential. Moreover, the work adds weight to the ongoing push for post-quantum cryptographic standards, reminding the crypto ecosystem that the security of underlying primitives must evolve alongside advances in computing power.




