There’s a new way to break RSA that’s faster than anything we’ve seen before

by | Oct 5, 2026 | Technology

There's a new way to break RSA that's faster than anything we've seen before

A new attack on RSA encryption has emerged that bypasses the traditional factoring approach cryptographers have long considered the primary vulnerability. Rather than attempting to factor large numbers, the attack uses a variant of the number field sieve algorithm developed in 2007, combined with properties called oracles found in certain cryptographic protocols.

The research demonstrates that attacking 1024-bit RSA keys through signature forgery requires approximately 265 operations and 1,380 core-years of computation, vastly less than the estimated 280 operations and 500,000 to 1 million core-years needed for traditional factoring. Testing on academic computing clusters showed the attack could be completed in a matter of months. For 2048-bit and 4096-bit keys, the method reduces security levels to 290 and 2119 respectively, below the 128-bit minimum standard required by the National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security.

Cryptography experts have expressed surprise at this conceptual breakthrough, as the field previously believed RSA security was fundamentally tied to the difficulty of factoring. Researchers noted that optimization through artificial intelligence and graphics processing units could further reduce these computational requirements, though their initial work was completed without such tools.

The practical implications remain limited for most current implementations. The attack only affects blind-signature or textbook RSA implementations, while the vast majority of RSA deployments use PKCS or PSS padding formats that provide additional protection. However, some real-world systems including Privacy Pass, used by Apple and Cloudflare, do employ the vulnerable implementation. The researchers note that key rotation practices commonly employed by major organizations reduce the likelihood of successful attacks.

This development is expected to accelerate cryptographic migration efforts already underway to prepare for quantum computing threats and to adopt alternative encryption methods resistant to both classical and quantum attacks.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI