In short: Cryptographers, including UC San Diego professor Nadia Heninger, demonstrated a practical attack that forges a valid RSA signature without computing the private key through factorization. The method combines a special number field sieve with a blind-signature "oracle" and is already practical against legacy 1024-bit keys. At risk are blind-signature systems, including Apple and Cloudflare's Privacy Pass protocol; implementations with PKCS or PSS padding, used in the vast majority of production systems, are unaffected. We covered which encryption protocols still hold up today in our piece on choosing the most secure VPN.
What happened
A team of researchers published a paper and code on GitHub showing how to produce a valid RSA signature without ever recovering the private key — cryptographers had long assumed the only way to forge a signature was to factor the modulus and derive the key directly. The story was independently confirmed by Habr and 3DNews, citing the original Ars Technica report: it spread across Russian-language tech outlets on September 29–30, 2026 as a notable cryptography event.
The core technique is a modified variant of the Special Number Field Sieve (proposed back in 2007), combined with repeated queries against a signing "oracle." Instead of fully factoring the modulus, the attack gathers data through a large number of valid signature requests and reconstructs enough information to forge a new signature — a so-called blind RSA signature attack, where a server signs data without seeing its contents.
Which keys and protocols are at risk
For a 1024-bit key, the attack requires roughly 2^65 operations and about 1,380 core-years of compute — noticeably less than the 2^80 operations and 500,000 to 1 million core-years needed for classical factorization of the same key size. For 2048-bit keys the estimate is around 2^90 operations, and for 4096-bit keys around 2^119: legacy short keys are within practical reach today, while longer keys remain out of reach for now, though the safety margin has shrunk considerably.
The main practical target is "textbook" blind RSA signature systems, most notably Privacy Pass, which Apple and Cloudflare use to anonymously verify request legitimacy without revealing a user's identity. Attacking Privacy Pass is estimated to require around 2^43 tokens — still substantial, but orders of magnitude less than "breaking RSA" in the everyday sense. Importantly, implementations using PKCS#1 or PSS padding — which underpin the vast majority of production systems, including TLS certificates, digital signatures, and banking protocols — are not affected by this attack.
What this means for everyday users
There's no reason for end users to panic: the attack needs specific conditions (an unpadded blind signature scheme) and an enormous number of requests to the signing server, so the researchers don't describe mass exploitation in ordinary scenarios. Still, it's a signal for the industry as a whole: RSA keys shorter than 2048 bits keep losing their safety margin faster than previously assumed, and developers of anonymous-authentication protocols should check whether their systems rely on a vulnerable textbook blind-signature implementation.
The practical takeaway for users is not to treat an algorithm's age as a guarantee of safety, and to pick services that keep their own cryptography current. LiMP VPN uses modern encryption protocols with long keys and no blind-signature schemes, and its no-logs policy means that even a theoretical flaw in a third-party protocol can't expose browsing history — there simply isn't one stored on the provider's side.
