A team of researchers from UC San Diego in the United States and Inria, the French computer science research institute, have forged digital signatures on a Hardware Security Module (HSM). They reconstructed the signing function of this physical security device without ever extracting the private key stored inside it. The findings were published in a scientific paper on the IACR Cryptology ePrint Archive on September 20.
The research serves as a stress test for institutional crypto custody providers, such as BitGo and other enterprise entities. Institutional-grade custody has long relied on tamper-resistant HSM hardware with one primary goal: ensuring that client private keys are never exposed to external environments under any circumstances.
What makes this finding stand out is not that its physical defenses were breached, but rather a mathematical vulnerability behind the system.
Sending Four Billion Random Numbers
The researchers began by disabling FIPS mode, a built-in security certification setting on the module. This step allowed the HSM device to sign raw, unformatted numbers using access provided by a specialized test key.
Once the setting was disabled, they flooded the security module with a massive volume of requests. The researchers submitted roughly four billion chosen random numbers, prompting the device to sign them one by one. Each response returned by the module was then subjected to mathematical analysis. Analyzing these millions of probe data points paved the way for the team to completely reconstruct the signing function from the outside.
The RSA cryptographic algorithm was the target of this maneuver. The security standard, formulated in 1977 by Ron Rivest, Leonard Adleman, and Adi Shamir, relies on the difficulty of factoring the product of two large prime numbers. Through this technique, the researchers bypassed physical protections without tampering with the key itself.
Impact on Bitcoin and Ethereum
For holders of major cryptocurrencies, this vulnerability does not reach their wallets. Major blockchains such as Bitcoin and Ethereum use elliptic curve digital signature algorithms (ECDSA) and Schnorr, rather than RSA cryptography. This algorithmic separation ensures that mainnet systems remain immune to signature manipulation methods targeting RSA-based hardware.
Although assets on major networks remain out of harm’s way, the experiment serves as a warning for the global crypto custody industry. Custody providers can no longer rely solely on physical barriers, as breaches can effectively penetrate through billions of mathematical queries.
Reported by Decrypt.
Read also: Bitget Breached for $351 Million Without Private Keys - CEO Blames North Korean Hackers
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




