Back to Blog
Cryptography

RSA Forgery Attack: Faster Than Factoring, But Not Against Padded Signatures

A newly implemented attack on RSA signatures is making headlines as a way to 'break RSA' without factoring. The underlying idea dates from 2007, and it only threatens unpadded signatures, which is not how RSA is deployed in practice.

PyramidLedger Research3 min read
Share

Key Takeaways

  • The attack forges RSA signatures. It does not recover the private key from the public key.
  • It only works against 'pure' RSA signatures with no formatting or padding, which is not how RSA is generally used in practice.
  • The underlying research dates from 2007. What is new is a working implementation.
  • It runs in subexponential time, faster than factoring but not polynomial. Researchers forged messages for 1024-bit RSA using 1380 CPU core-years.

Headlines this week describe a new way to break RSA that bypasses factoring. The coverage needs careful reading. As Bruce Schneier points out, most of the alarming framing does not survive contact with the details.

What the attack actually does

This is a signature forgery attack. An attacker can produce valid digital signatures on messages without holding the private key. It is not a key-recovery attack: the private key is not derived from the public key, and RSA encryption is not the target.

It also sidesteps integer factoring. That is why it is notable, since factoring hardness is the assumption most people associate with RSA security. But bypassing factoring is not the same as breaking RSA in general.

Why the scope is narrow

The attack works only against pure signatures, meaning signatures computed over raw values with no formatting or padding. Schneier notes that this is not generally how RSA is used in practice. Deployed schemes wrap the message hash in structured padding before the private-key operation, and verifiers check that structure. The attack as described does not apply to that setting.

Not new, but newly implemented

The original research is from 2007 (IACR ePrint 2007/424). What is new is a concrete implementation, documented in a 2026 paper. That matters because a demonstrated implementation gives us real cost figures rather than asymptotic estimates.

How fast is 'faster'?

The algorithm is subexponential-time, faster than factoring but not polynomial-time. In the researchers' demonstration they forged messages for 1024-bit RSA using 1380 CPU core-years. That is a significant but bounded amount of compute, and it is a cost measured against a modulus size that is already considered weak for new deployments.

What security teams should do

  • Check your signature schemes. Confirm that libraries and protocols use a standard padded signature scheme, not raw or textbook RSA signing.
  • Audit custom code. Bespoke implementations that apply the private-key operation directly to a value are the ones that fit the attack's prerequisites.
  • Do not panic-rotate. Nothing in the reporting suggests padded, standards-based RSA signatures are affected.
  • Treat it as a reminder. Padding is a security requirement for signatures, not an optional formatting detail.

Bottom line

This is a useful reminder about why RSA is never used raw, and an interesting data point on the cost of a 2007-era idea when actually implemented. It is not a break of RSA as deployed.

Frequently asked questions

Frequently Asked Questions

Does this attack recover RSA private keys?

No. It is a forgery attack that lets an attacker produce valid signatures. It does not recover the private key from the public key.

Are standard padded RSA signatures vulnerable?

According to Schneier's summary, the attack only works against pure signatures with no formatting or padding, which is not how RSA is generally used in practice.

Is this attack actually new?

The original research dates from 2007. What is new is the implementation, which forged messages for 1024-bit RSA using 1380 CPU core-years.

Sources

  1. 1New Attack Against RSA — Schneier on Security
  2. 2There's a new way to break RSA that's faster than anything we've seen before — Ars Technica
  3. 3Paper: eprint 2026/2131 — IACR ePrint Archive
  4. 4Original 2007 research: eprint 2007/424 — IACR ePrint Archive
Share

Read next