Researchers have found a new classical-computing attack on RSA encryption that reduces the cost of breaking keys to a point where even 2048-bit systems fall short of accepted security standards. The finding poses little to no practical threat in the immediate term, but it could force early replacement of widely deployed encryption.
How the attack works
For decades, the assumption behind RSA has been simple: to forge a signature, you must first crack the key. That means factoring the large integer that defines the key, a task that was considered impractical for sufficiently large keys. Now a team led by Nadia Heninger of the University of California at San Diego has shown that assumption may no longer hold.
The attack does not require factoring the key. Instead, it finds a way to produce valid signatures directly. Factoring a large integer is a hard problem, but the new method reduces the required computing resources by orders of magnitude.
What the attack achieves
The method applies to 1024-bit keys, which were once considered weak and are now deprecated. For those, the attack brings the breakage into the realm of possibility much sooner than previously estimated.
Even more concerning is the effect on larger keys. The attack reduces the security of 2048-bit and 4096-bit keys to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security all require that any cryptosystem provide a level of no less than 128 or more bits, meaning the operations required must exceed 2128.
The researchers have shown that the math works. The gap between theory and practice remains significant, but the direction is clear.
Why this matters
Karsten Nohl, a cryptography expert and the head of innovation at Allurity, put the stakes in perspective in an interview. “If this result holds up under peer review, it would indeed be a conceptual break-through,” he said. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”
The attack also changes the economics of crypto-cracking. For 1024-bit RSA, factoring was thought to be very expensive, albeit probably doable with the computational resources of large tech companies or the NSA — on the order of tens of millions of dollars of computation time for a single key. The new method lowers that bar.
For 2048-bit RSA, the attack reduces security to unacceptable levels, according to the researchers. The fact that it falls below the accepted threshold is the core concern.
The limits of the threat
The immediate risk is small. The attack requires more computation than almost anybody — short of nation-states or companies with massive resources — can achieve.
That framing is important. This is not a vulnerability that a hacker can exploit tomorrow. It is a warning that the mathematical foundations of RSA are weaker than assumed, and that systems using smaller keys are at greater risk than previously believed.
The path forward
The research has taken cryptographers by surprise because it introduces signature forgery, a new way to break RSA keys without factoring. The finding is a conceptual breakthrough, not an operational crisis.
Peer review will test the result. Until then, the finding stands as a warning rather than a mandate. Systems using 1024-bit keys should be treated as compromised in principle, even if the practical attack remains out of reach for most attackers.
The broader lesson is that cryptographic assumptions deserve regular testing. RSA has been the standard for decades, and it has held up well. This research shows that confidence can slip away quickly when the assumptions change.
| Key size | Previous risk | New risk |
|---|---|---|
| 1024-bit | Weak, deprecated | Within practical reach |
| 2048-bit | Strong | Below accepted security threshold |
| 4096-bit | Out of reach | Reduced security |
The table captures the shift. The attack does not break RSA entirely, but it changes the cost-benefit analysis for anyone holding a key. A system that was secure by design is now secure only until the next attack arrives.
The immediate takeaway is simple: systems using 1024-bit keys should be treated as compromised in principle, even if the practical attack remains out of reach for most attackers. The attack reduces the security of 2048-bit and 4096-bit keys to unacceptable levels, according to the researchers, and that is a problem that will need fixing sooner or later.
The research is a reminder that cryptographic security is not permanent. It is a balance of cost and effort, and the balance shifts over time. The new attack shows that the cost of breaking RSA has dropped, and the security thresholds have shifted with it.
For now, the research stands as a warning. The math has changed, and the systems built on that math will need to adapt.
Source material: “There's a new way to break RSA that's faster than anything we've seen before,” Ars Technica.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

