BTC — +0.00% ETH — +0.00% SOL — +0.00% BTC — +0.00% ETH — +0.00% SOL — +0.00%
Markets Via Decrypt

Cryptographic Attack Demonstrates Vulnerability in Hardware Vaults

A team of researchers has successfully demonstrated a novel cryptographic attack that bypassed the security of a hardware vault without extracting its private key, raising concerns for crypto asset storage.

The attack, led by researchers at UC San Diego and presented at a recent security conference, targeted a device known as a Hardware Security Module (HSM) that uses the RSA encryption standard. The researchers devised a method to act as a malicious server and trick the HSM into decrypting data using its stored private key.

The critical flaw exploited a known vulnerability in a protocol used for secure online transactions, not a flaw in the RSA algorithm itself. By impersonating a legitimate server with specially crafted ciphertext, the researchers could repeatedly query the HSM to deduce the private key’s function.

While the specific HSM model was not named, the research demonstrates a practical threat to cryptographic hardware widely used by enterprises and exchanges to secure keys. The team suggested that many commonly used HSMs could be vulnerable to similar adaptive attacks, underscoring the need for more robust implementation of cryptographic protocols.

Original reporting: Decrypt