Researchers including Laura Shea and Nadia Heninger at the University of California San Diego demonstrated an RSA signature-forgery attack without factoring the modulus or recovering the private key. Implementing an attack first proposed in 2007 with a variant of the Number Field Sieve, the team forged signatures for a 1024-bit RSA key using approximately 1,380 CPU-years of computation over five months on an academic cluster. That is substantially below the estimated 500,000 to one million CPU-years needed to factor a comparable modulus, but the attack requires temporary access to an oracle performing unpadded private-key RSA operations.
The demonstration is not a general break of RSA or an immediate threat to most deployments. Standard PKCS#1 v1.5 and RSA-PSS signing interfaces do not supply the required raw oracle. Potential exposure includes some blind RSA signature implementations, hardware security module interfaces, and Privacy Pass deployments, although enormous query requirements and regular key rotation limit practical exploitation. The researchers estimate attack-specific security levels of approximately 90 bits for RSA-2048 and 119 bits for RSA-4096; these estimates should not be applied to RSA deployments lacking the required oracle. Security teams should review interfaces that expose raw private-key operations rather than assume all RSA signatures are affected.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A theoretical attack using a variant of the Number Field Sieve was proposed in 2007. It provided the basis for the later demonstration of RSA signature forgery without factoring the modulus.
The researchers released the complete attack implementation on GitHub. The repository's FAQ explained the attack's limitations, including its dependence on access to a raw signing oracle.
The researchers described their results in “Forging 1024-bit RSA signatures in nearly SNFS time,” explaining that the attack requires temporary access to an unpadded private-key RSA oracle and does not apply to standard PKCS#1 v1.5 or RSA-PSS signing interfaces. Under the required oracle conditions, they estimated attack-specific security levels of approximately 90 bits for 2048-bit RSA and 119 bits for 4096-bit RSA.
A team including UC San Diego researchers Laura Shea and Nadia Heninger implemented the attack and forged signatures for a 1024-bit RSA key without factoring its modulus or recovering its private key. The demonstration ran over five months on an academic CPU cluster and consumed approximately 1,380 CPU core-years of computation.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.