This event serves as a crucial evaluation of key security protocols. According to BitGo, institutional custody services utilize hardware security modules (HSMs)—tamper-resistant devices designed to protect keys—ensuring that the keys remain securely stored within the hardware. In this case, the key remained within the HSM, yet researchers were still able to forge signatures.
They did disable the HSM’s FIPS mode, which is a certified security feature, allowing it to sign unformatted numerical values and employed a test key created by them.
The researchers instructed the device to sign nearly 4 billion numbers of their selection and then performed calculations based on the outputs. Imagine a vault that remains locked but can imprint any blank paper you slip beneath its door. If you ask often enough, you may eventually learn how to replicate the imprint.
Understanding Signatures
Each time you authorize a transaction, your wallet uses your private key to sign it. This digital signature serves as verification that the key holder authorized the transaction and that the message remained unchanged during transmission.
One method to establish this proof is RSA, introduced in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, with “S” representing Shamir.
The fundamental principle of RSA is that while multiplying two large prime numbers is straightforward, breaking down the resultant product (factoring) is extremely challenging. According to the researchers, the security of RSA is largely based on this difficulty, though it has never been definitively shown that compromising RSA equals factoring. It’s worth noting that this research team did not factor any numbers.
Implications for Users
Standard RSA signatures incorporate padding—a process of scrambling and formatting (like PKCS#1 v1.5 or PSS) that occurs prior to the mathematical operations—and these padded signatures do not create a vulnerable oracle. The researchers suggest that their findings likely do not present an immediate risk to most current RSA implementations. The paper in question is a preprint.
Some systems intentionally provide access to the oracle. RSA-based blind signatures allow a server to sign data without actually knowing its content, as seen in a variant of Privacy Pass. According to Cloudflare, Apple employs a version of Privacy Pass, enabling users to verify they have passed a check, like a CAPTCHA, without revealing their identity.
Blind signatures have a foundation in cryptography, with David Chaum employing the method when he established DigiCash in 1989.
The Quantum Threat Looms Larger
Headlines declaring “RSA is compromised” are not new. In January 2023, Chinese researchers claimed to have developed a quantum approach threatening RSA, but had only been able to factor a 48-bit number, leading experts to dismiss their findings. Now, the demonstration involves an actual 1,024-bit key, albeit with caveats concerning the oracle.
The researchers argue that their findings provide classical evidence for the necessity of moving away from RSA as we transition to post-quantum cryptography, which aims to establish encryption robust against quantum computing.
For Bitcoin enthusiasts, the quantum concern revolves around elliptic-curve signatures. Researchers at Caltech estimated that between 10,000 and 20,000 qubits—the quantum equivalent of bits—could suffice to execute Shor’s algorithm, the technique that poses risks to these signatures.
Google has set a target of 2029 to complete the transition of its systems to post-quantum cryptographic standards.
