There’s a new way to break RSA that’s faster than anything we’ve seen before

by | Oct 8, 2026 | Technology

There's a new way to break RSA that's faster than anything we've seen before

Cryptographers have identified a new attack method against RSA encryption that does not rely on factoring large integers, marking a significant conceptual breakthrough in cryptography research. The novel approach, developed by researchers including Nadia Heninger at the University of California at San Diego, enables signature forgery attacks that require far fewer computational resources than traditional factoring methods.

The practical implications vary by key size. For 1024-bit RSA keys, the attack proved feasible on an academic CPU cluster over a period of months—substantially less demanding than current estimates for factoring, which would require resources accessible only to major technology companies or nation-states. The attack reduces security levels from the required minimum of 128 bits to 65 bits for 1024-bit keys, 90 bits for 2048-bit keys, and 119 bits for 4096-bit keys. Researchers note these figures could potentially decrease further, as they conducted their work without artificial intelligence or GPU acceleration.

The attack specifically targets blind-signature implementations of RSA, commonly referred to as textbook RSA. The majority of widely deployed RSA systems use PKCS or PSS padding, which adds additional data before encryption and provides protection against this type of attack. However, some real-world systems continue using unpadded RSA, including Privacy Pass, a protocol used by Apple and Cloudflare for anonymous authentication. An attack on Privacy Pass would require requesting approximately 2 to the 43rd power of tokens, a volume comparable to Cloudflare’s typical daily network traffic.

The technique employs a variant of the number field sieve algorithm, a mathematical approach originally developed in 2007. By querying cryptographic protocol properties known as oracles, attackers can accumulate sufficient information to compromise the encryption. The computational requirements represent a dramatic reduction compared to factoring: while factoring a 1024-bit key requires approximately 2 to the 80th power operations and hundreds of thousands to over one million CPU core-years, the signature forgery method requires 2 to the 65th power operations and approximately 1,380 core-years.

Experts and researchers emphasize the attack poses limited immediate threat to modern RSA implementations, particularly those using standard padding schemes. Nevertheless, the discovery heightens urgency for transitioning to quantum-resistant cryptographic systems, as cryptographers worldwide race to develop alternatives that can withstand both classical and quantum computing attacks.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI