Researchers Forge Signatures Without Stealing Vault Keys
Researchers from UC San Diego and France's Institute for Research in Computer Science successfully impersonated a tamper-resistant hardware security module without extracting its private key. The security demonstration, detailed in a preprint paper submitted to the IACR Cryptology ePrint Archive on September 20, offers a rigorous look at how digital keys are currently guarded.
The exploit does not threaten major digital asset networks. Bitcoin relies on an elliptic curve digital signature algorithm, or ECDSA, and its curve also supports Schnorr signatures. Ethereum and most major blockchains utilize the same cryptographic standard. The researchers’ paper exclusively targets Rivest-Shamir-Adleman cryptography, an alternative signature scheme commonly known as RSA.
To execute the forgery, the research team disabled the hardware security module's certified security setting, known as FIPS mode, allowing the device to sign unformatted numbers. Utilizing their own test key, they instructed the module to sign roughly four billion distinct numbers of their choosing. By performing calculations on the hardware's responses, the researchers deduced how to fabricate digital signatures themselves without ever opening the cryptographic vault.
Evaluating Custody Infrastructure
Hardware security modules are physical boxes utilized by institutional custody providers, such as BitGo, to ensure private keys never exist outside the device. Every time a transaction is confirmed, a digital signature proves the key holder approved it and that the message remained unaltered. In this academic test, the private test key remained firmly isolated within the device, yet the research team still successfully forged those proofs.

RSA, formulated in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, anchors its security on the immense difficulty of factoring enormous prime numbers. The academic team did not actually factor any numbers. Instead, they weaponized the hardware's continuous responses into an exploitable oracle. Standard RSA deployments use specific padding steps, formatting procedures like PSS or PKCS#1 v1.5, that scramble data before the mathematical signing occurs. Because padded signatures do not create the exploitable oracle, the authors stated that their attack likely presents no immediate operational threat to modern RSA setups.
However, certain cryptographic systems are designed to hand out an oracle intentionally. RSA-based blind signatures allow servers to sign information without viewing the contents. Cryptographer David Chaum implemented this technique when establishing DigiCash in 1989. Today, Cloudflare notes that Apple uses a variant of Privacy Pass so users can prove they passed checks, like CAPTCHAs, without revealing their identities.
The Post-Quantum Horizon
Claims of compromised RSA cryptography surface periodically. In January 2023, Chinese researchers asserted they possessed a quantum method that threatened the encryption standard, but experts dismissed the claim after noting the team only factored a 48-bit number. By contrast, the newly published demonstration manipulated an actual 1,024-bit key, although it required the massive oracle workaround.
The paper's authors position their results as classical evidence supporting an industry-wide transition away from RSA in favor of encryption robust enough to withstand future quantum computers.
For networks like Bitcoin, the quantum threat centers on elliptic-curve signatures. At the end of March, researchers at Caltech estimated that running Shor's algorithm, the mathematical method necessary to break these signatures, would require between 10,000 and 20,000 qubits. The broader technology sector is already preparing for this shift, with Google establishing a 2029 deadline to finish migrating its internal systems to post-quantum cryptography.


