Forging 1024-bit RSA signatures in nearly SNFS time, sans factoring N

matthew_d_green · x · 2026-09-22

A UCSD team published a paper and code implementing a variant of the number field sieve showing that temporary access to a raw, unpadded RSA-1024 signing/decryption oracle (e.g., an HSM) grants a permanent ability to forge signatures and decrypt ciphertexts — effectively stealing the secret key without ever factoring N, and at far less computation than factoring would require.

Related event: UCSD Researchers Forge 1024-bit RSA Signatures Near SNFS Time(3 posts)→

Original post →

More from Safety

Safety channel →