tradingkey.logo

tradingkey.logo
怜玢


Researchers forge 1024-bit RSA signature without extracting private key

CryptopolitanSep 29, 2026 4:53 AM
facebooktwitterlinkedin
すべおのコメントを芋る0


A team of researchers from UC San Diego showed that a 1024-bit RSA signature can be forged by sending multiple queries to a hardware security module (HSM). In this case, the private key was never extracted from the device.

This result implies yet another form of risk for crypto custodians: keeping the key inside tamper-proof hardware is not sufficient if the attacker hacks the systems that have been authorized to use it.

Forging a signature the key never signed

In IACR ePrint 2026/2131, Laura Shea, Miro Haller, Adam Suhl and Nadia Heninger of UC San Diego, with Emmanuel Thomé of Inria, describe how temporary access to a raw RSA signing oracle can eventually give an attacker the ability to forge signatures offline.

The attack process consisted of 2^32 basic signing requests: this counts to a little more than 4.3 billion queries and results in 1,380 CPU core-years used of computing time over a period of five calendar months.

In comparison with the work done, as calculated by the researchers’ project materials, factoring the same 1024-bit RSA modulus would take approximately 500,000-1,000,000 core-years. Most of the work that is conducted is done only once during precomputing; afterwards, forging of a chosen signature should require around 180 core-years.

The algorithm used was invented back in 2007. What has changed is that the team of researchers actually succeeded in conducting a real attack, as noted by Bruce Schneier on September 28:

“What is new is the implementation.” — Bruce Schneier

Why unpadded signing is the whole trick

An essential restriction exists with respect to this type of attack: it requires the availability of a raw unpadded RSA signing or decryption oracle. Standard RSA signatures using PKCS#1 v1.5 or RSA-PSS do not provide this access. Therefore, this attack cannot be considered a practical attack on properly implemented RSA.

As Decrypt noted, the researchers turned off the certified FIPS mode on the HSM and used a test key of their own.

According to the paper, the occurrence of raw signing access can be seen in HSM APIs and RSA blind-signature systems. The paper then goes on to state that RFC 9474, for instance, explains a scenario where the server signs the blinded message without any access to the original message.

The study uses Apple’s figure of 2.3 billion active devices to show how fast concurrent requests can pile up. At one token per minute, a single device would need about 17 million years to reach 2^43 queries. But if you look at the full figure of 2.3 billion devices, the same number of requests can be made in just about 2.3 days.

Signing interfaces as part of the perimeter

For crypto custodians, locking the private key in a safe does not provide complete safety. The APIs, approval processes, and automated systems that utilize the private key pose their own dangers.

This concern is already reflected in the industry. According to EY’s 2026 survey, security of digital coins, as well as key-signing procedures, have become far more significant in the custodian selection process. The Common Supervisory Action of ESMA, launched on July 8, also focus on the scrutiny of key and storage management, transaction controls and incident response.

According to the researchers, RSA with a signature oracle provides 15-30 bits lower security than factoring-based estimates for typical 1024-4096-bit keys. In this model, 4096-bit RSA does not even provide the security of 128-bit encryption.

Not a Bitcoin or Ethereum break

The paper is about RSA. Ethereum uses secp256k1 ECDSA, while Bitcoin uses secp256k1 ECDSA and Schnorr signatures, so the demonstrated attack does not apply to their transaction-signing systems.

The larger issue concerning custody risk isn’t something that’s entirely fresh. A Cryptopolitan report on September 20 has indicated how compromised signing authorities have drained around $2 million from Fetch.ai and NuNet. While the case above involved an individual obtaining the key, this report shows that the attacker might gain signing authority without ever obtaining the key.

If you're reading this, you’re already ahead. Stay there with our newsletter.

免責事項本サむトで提䟛する情報は教育・情報提䟛を目的ずしたものであり、金融・投資アドバむスずしお解釈されるべきではありたせん。

コメント (0)

$ボタンをクリックし、シンボルを入力しお、株匏、ETF、たたはその他のティッカヌシンボルをリンクしたす。

0/500
コメントガむドラむン
読み蟌み䞭...

おすすめ蚘事

マむクロン察サンディスクAIデヌタセンタヌのブヌムが加速するなか、買いなのはどちらのメモリ株か

AIデヌタセンタヌのサプラむチェヌンにおいお、メモリずストレヌゞは䞍可欠な存圚です。AIアクセラレヌタがデヌタ転送のために高垯域幅メモリを必芁ずする䞀方、孊習および掚論システムは、モデル、デヌタ、䞭間結果の保存においお倧容量DRAMや゚ンタヌプラむズ向けSSDに䟝存しおいたす。䞻芁䌁業のなかで、マむクロンMUはDRAM、HBM、NANDの党般にわたっお存圚感を維持しおいるのに察し、サンディスクSNDKはNAND型フラッシュメモリず゚ンタヌプラむズ向けデヌタセンタヌストレヌゞを䞻軞に眮いおいたす。䞡瀟ずもにAIストレヌゞ需芁の恩恵を受けおいたすが、投資家が最終的に芋極めるべきは、事業が倚角化されたプラットフォヌムず、より高い匟力性を持぀NANDピュアプレむのシクリカル銘柄のどちらがより優れた資産配分の遞択肢であるかずいう点です。

゚ヌビディア株䟡予想過去最倧の自瀟株買い開始で300ドル挑戊ぞ

TradingKey - 米東郚時間9月28日、ハむテク株党般に䞋抌し圧力がかかるなか、゚ヌビディアNVDAの株䟡は、新たに発衚した倧芏暡な自瀟株買い蚈画が䞻因ずなり逆行高ずなった。9月28日、゚ヌビディアは取締圹䌚が既存の株匏買戻し授暩枠に1,500億ドルを远加承認し、残りの自瀟株買い可胜枠が2,350億ドルに達したず発衚した。同瀟は2028䌚蚈幎床末たでにこのプログラムを実行する蚈画であり、米囜株匏垂堎の歎史においお最倧芏暡の自瀟株買いずなる。発衚を受け、同日の゚ヌビディア株は1.68%高の228.86ドルで取匕を終え、日䞭高倀の233.21ドルを付ける堎面もあった。同期間にNasdaq指数が0.92%䞋萜したのに察し、自瀟株買いのニュヌスが株䟡に察しお明確な独立した䞋支えをもたらしたこずを瀺しおいる。
tradingkey.logo
リスク告知圓瀟りェブサむト及びモバむルアプリは特定の投資商品に関する䞀般的な情報のみを提䟛しおおり、Finsightsは金融アドバむスや投資商品の掚奚を行うものではありたせん。本情報の提䟛をもっおFinsightsが投資助蚀を行っおいるず解釈されるこずはありたせん。
投資商品には元本割れを含む重倧なリスクが䌎い、党おの投資家に適するものではありたせん。なお、過去の運甚実瞟は将来の成果を保蚌するものではありたせん。
Finsightsは、第䞉者広告䞻たたは提携先が圓瀟りェブサむト・モバむルアプリ䞊に広告を掲茉するこずを蚱可する堎合があり、これら広告䞻から広告ぞの反応に基づく報酬を受けるこずがありたす。
© 著䜜暩: FINSIGHTS MEDIA PTE. LTD. 無断耇写・転茉を犁じたす。