Crypto
Home›Crypto›Market Structure›RSA attack impersonates a hardware vault without extra…
RSA attack impersonates a hardware vault without extracting its key
Researchers say they forged signatures after switching off a hardware security module's FIPS mode, highlighting risks even when keys stay inside the device.
Researchers from UC San Diego and France's Institute for Research in Computer Science demonstrated an attack in which a hardware security module was impersonated without ever extracting the private key from the tamper-resistant device, according to Decrypt.
The team submitted the work to the IACR Cryptology ePrint Archive on September 20 and framed the exercise as a stress test for how custody setups protect keys, Decrypt reported. The researchers said the attack targeted Rivest-Shamir-Adlemen cryptography rather than the signature schemes used by Bitcoin and Ethereum.
Decrypt noted that institutional custody providers such as BitGo use hardware security modules so keys do not exist outside the device, but the researchers said they were still able to forge signatures. They reported disabling the module's FIPS mode and using a test key of their own.
The researchers also emphasized that the result is not a Bitcoin or Ethereum break, and that the paper applies to RSA signature handling rather than ECDSA or Schnorr signatures used on major public blockchains, Decrypt added.
Latest closeBitcoin $83,181.53 ▼1.5%|Ethereum $2,670.80 ▼0.6%