Security· ★★★· neutral·

Researchers Forged RSA Signatures Inside a Hardware Security Module Without Extracting the Key

  • —The attack required about 2^32 (roughly 4 billion) signing requests and 1,380 CPU core-years
  • —The key never left the hardware security module, yet signatures were still forged
  • —Bitcoin and Ethereum use ECDSA/Schnorr, not RSA, so they are not directly affected
  • —The authors say most modern RSA deployments with padding face no immediate threat
Why it matters: The result highlights risks in hardware key custody and strengthens the case for migrating to post-quantum cryptography.
Source: Decrypt