Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Kids Are Using NPR Podcast Comments as Secret Group Chats

28 minutes ago

Robinhood (HOOD) adds AI agents, perps and weekend trading in push to win active traders

51 minutes ago

Greece Gets First MiCA Entrants, HCMC Denies Binance-Lagarde Claim

52 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Tuesday, September 29
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»A Clever RSA Attack Fooled a Hardware Vault—Here’s What It Means for Crypto
Cryptocurrency & Free Speech Finance

A Clever RSA Attack Fooled a Hardware Vault—Here’s What It Means for Crypto

News RoomBy News Room1 day agoNo Comments4 Mins Read2 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
A Clever RSA Attack Fooled a Hardware Vault—Here’s What It Means for Crypto
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Researchers at UC San Diego and France’s INRIA forged RSA signatures on a 1,024-bit key inside a hardware security module, the kind of device custodians use to guard crypto keys, without extracting the key.
  • Bitcoin and Ethereum sign transactions with elliptic-curve signatures such as ECDSA rather than RSA, and the paper’s claims cover RSA only.
  • The attack needed about 2^32 signing requests (roughly 4 billion) and 1,380 CPU core-years, and the authors say it likely poses no immediate threat to most modern RSA deployments, which use padding.

Researchers at UC San Diego and France’s Institute for Research in Computer Science impersonated a hardware security module—a tamper-resistant device that stores private keys and signs on request—without ever pulling the key out of it. They detailed the attack in a paper submitted to the IACR Cryptology ePrint Archive on September 20.

But don’t panic, crypto holders. This is not a Bitcoin or Ethereum break. Bitcoin uses an elliptic curve digital signature algorithm, or ECDSA. (Its curve also supports Schnorr signatures.) Ethereum, and most of the bigger blockchains, use the same. This paper is about Rivest-Shamir-Adlemen cryptography, or RSA, a different signature scheme.

Myriad: How high will Bitcoin go? Click to make your prediction.

Still, the result is a stress test of how keys get guarded. Institutional custody providers, per BitGo, use a hardware security module—a tamper-resistant box that companies use to guard keys— so that keys never exist outside the device. Here the key never left the device, and the researchers forged signatures anyway.

They did switch off the hardware security module’s FIPS mode, a certified security setting, so it would sign unformatted numbers, and they used a test key of their own.

They asked the box to sign roughly 4 billion numbers of their choosing, then did math on the answers. Think of a vault that never opens but stamps any blank paper you slide under the door. Ask enough times, and you can learn to make the stamp yourself.

What’s a signature?

Every time you confirm a transaction, your wallet signs it with your private key. That digital signature is the proof that the key holder approved it, and that nobody altered the message on the way.

RSA is one way of building that proof, created in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, the “S” in the name.

BitcoinBTC · USD

$83,476−3.59%

Sep 21Sep 23Sep 25Sep 27Sep 28

$87.2k$85.7k$84.2k$82.7k

24h HighHigh$84,945

24h LowLow$82,581

VolVol$1.8B

Market projectionsOdds by Myriad

→

The key idea of RSA is that multiplying two enormous prime numbers is easy, but splitting the result back apart (called factoring) is brutally hard. The authors write that RSA’s security is generally understood to rest on that difficulty, though breaking RSA has never been proven equivalent to factoring. This team never factored anything.

Who is affected

Standard RSA signing applies padding—a scrambling and formatting step, such as PKCS#1 v1.5 or PSS, that runs before the math—and padded signatures don’t create the exploitable oracle. The authors say the attack likely poses no immediate operational threat to most modern RSA deployments. The paper is a preprint.

Some systems hand out the oracle on purpose. RSA-based blind signatures let a server sign something without seeing it, which is how one variant of Privacy Pass works. Cloudflare says Apple uses a version of Privacy Pass so users can prove they passed a check, like a CAPTCHA, without revealing who they are.

Blind signatures have crypto roots. Cryptographer David Chaum used the technique when he founded DigiCash in 1989.

The bigger threat is still quantum

“RSA is broken” headlines have a track record. In January 2023, Chinese researchers claimed a quantum method that threatened RSA, but had only factored a 48-bit number, and experts dismissed it. This time the demonstration is an actual 1,024-bit key, with an asterisk the size of the oracle.

The authors call their result classical evidence for moving away from RSA during the post-quantum transition, meaning the shift to encryption built to survive quantum computers.

For Bitcoin, the quantum question is elliptic-curve signatures. Caltech researchers estimated at the end of March that 10,000 to 20,000 qubits—the quantum version of bits—could be enough to run Shor’s algorithm, the method that threatens these signatures.

Google has set 2029 as its deadline to finish migrating its own systems to post-quantum cryptography.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

Kids Are Using NPR Podcast Comments as Secret Group Chats

28 minutes ago
Cryptocurrency & Free Speech Finance

Robinhood (HOOD) adds AI agents, perps and weekend trading in push to win active traders

51 minutes ago
Cryptocurrency & Free Speech Finance

Greece Gets First MiCA Entrants, HCMC Denies Binance-Lagarde Claim

52 minutes ago
Cryptocurrency & Free Speech Finance

Cboe’s New S&P Deal Opens the Door to Tokenized Options

54 minutes ago
Media & Culture

Beware the Rush to Judgment in the Cornell Rape Case

1 hour ago
Cryptocurrency & Free Speech Finance

OpenAI valuation could hit $1.4T in new funding round: Report

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Robinhood (HOOD) adds AI agents, perps and weekend trading in push to win active traders

51 minutes ago

Greece Gets First MiCA Entrants, HCMC Denies Binance-Lagarde Claim

52 minutes ago

Cboe’s New S&P Deal Opens the Door to Tokenized Options

54 minutes ago

Beware the Rush to Judgment in the Cornell Rape Case

1 hour ago
Latest Posts

OpenAI valuation could hit $1.4T in new funding round: Report

2 hours ago

Ethereum Gets Another Privacy Boost as Aztec Brings Back zk.money

2 hours ago

While the Country Rejects ALPR Mass Surveillance, SF Settles for Weak Safeguards

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Kids Are Using NPR Podcast Comments as Secret Group Chats

28 minutes ago

Robinhood (HOOD) adds AI agents, perps and weekend trading in push to win active traders

51 minutes ago

Greece Gets First MiCA Entrants, HCMC Denies Binance-Lagarde Claim

52 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.