Security/ cryptography · rsa · cryptanalysis · security research

Researchers Claim Faster Path to Forging 1024-bit RSA Signatures

A new preprint claims 1024-bit RSA signatures can now be forged nearly as fast as the special number field sieve can factor specially shaped numbers.

A newly published preprint claims a way to forge 1024-bit RSA signatures almost as fast as the special number field sieve (SNFS) can factor numbers with a convenient algebraic shape.

The paper appeared on the IACR's eprint archive on September 24, 2026, describing an attack that approaches 'nearly SNFS time' for forging signatures under 1024-bit RSA. SNFS is dramatically faster than the general number field sieve (GNFS), but it has historically only applied to integers built with a specific mathematical structure, not the moduli that RSA implementations are designed to generate. The paper's framing suggests the authors found a way to extend that speed advantage to signature forgery more broadly. The work is a preprint: it has not yet been through peer review or independent verification.

1024-bit RSA has been considered too weak for serious use for well over a decade, and standards bodies pushed the industry toward 2048-bit keys years ago. Even so, 1024-bit keys persist in old certificates, embedded hardware, and legacy protocols nobody has prioritized retiring. A faster, more practical forgery technique narrows the gap between 'theoretically broken' and 'broken this afternoon,' which matters most for exactly the systems least likely to get patched.

Claims of speed records in cryptography are common; whether this one survives scrutiny from other cryptographers is the number actually worth watching.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →