Researchers from UC San Diego have demonstrated that a 1024-bit RSA signature can be forged by sending multiple queries to a hardware security module (HSM), even without extracting the private key from the device. The finding underscores a potential vulnerability for cryptocurrency custodians: keeping private keys in tamper-proof hardware is insufficient protection if attackers gain access to the systems authorized to use those keys.
How the Attack Works
According to a paper presented by Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger of UC San Diego, and Emmanuel Thomé of Inria, temporary access to a raw RSA signing oracle can eventually allow attackers to forge signatures offline.
The attack required approximately 2^32 basic signing requests—just over 4.3 billion queries—consuming 1,380 CPU core-years of computing time over five calendar months. By comparison, factoring the same 1024-bit RSA modulus would require approximately 500,000 to 1,000,000 core-years. Most computational work occurs during an initial precomputation phase; forging subsequent chosen signatures requires around 180 core-years.
Critical Limitation: Unpadded Signing Required
The attack has a significant restriction: it requires access to a raw, unpadded RSA signing or decryption oracle. Standard RSA signatures using PKCS#1 v1.5 or RSA-PSS do not provide this access, meaning the attack cannot be considered practical against properly implemented RSA systems.
The researchers disabled the certified FIPS mode on the HSM and used a test key to conduct their demonstration. According to the paper, raw signing access could occur in HSM APIs and RSA blind-signature systems, including scenarios described in RFC 9474 where servers sign blinded messages without access to the original message.
Scale and Speed Considerations
The paper notes that while a single device making one query per minute would require approximately 17 million years to reach 2^43 queries, distributed across Apple's figure of 2.3 billion active devices, the same number of queries could theoretically be completed in approximately 2.3 days.
Implications for Custody and Key Management
For cryptocurrency custodians, the research highlights that hardware security alone provides incomplete protection. The APIs, approval processes, and automated systems that utilize private keys present their own security risks.
The industry has already begun addressing these concerns. EY's 2026 survey found that security of digital assets and key-signing procedures have become more significant factors in custodian selection. Additionally, the European Securities and Markets Authority (ESMA) launched a Common Supervisory Action on July 8 focusing on scrutiny of key and storage management, transaction controls, and incident response.
According to the researchers, RSA signatures with a signing oracle provide 15-30 bits lower security than factoring-based estimates for typical 1024-4096-bit keys. Under this model, 4096-bit RSA does not provide the security equivalent of 128-bit encryption.
Limited Impact on Major Cryptocurrencies
The demonstrated attack targets RSA systems. Ethereum uses secp256k1 ECDSA, while Bitcoin uses secp256k1 ECDSA and Schnorr signatures, meaning the attack does not apply to their transaction-signing mechanisms.
The broader concern regarding custody risk is not new. A previous report documented that compromised signing authorities drained approximately $2 million from Fetch.ai and NuNet, demonstrating that attackers can gain signing authority without necessarily obtaining the private key itself.


