For decades, the security of the RSA cryptosystem has been understood to be finite, threatened ultimately by the advent of practical quantum computing, which estimates suggest could arrive anywhere from three to twenty or more years from now. But new research has shown that classical computing alone can attack RSA more efficiently than anything seen before.
The finding relies on a new method of breaking RSA keys without factoring them, instead forging signatures directly. According to researchers, this approach reduces the required computing resources by orders of magnitude compared with existing classical attacks.
Despite the theoretical advance, the attack is not an immediate practical concern. Even against the deprecated use of 1024-bit keys, the method demands more computation than almost any organisation — short of a nation-state or a company with massive resources — could realistically mount. Widely used RSA implementations remain safe, researchers said.
Nonetheless, the research has taken cryptographers by surprise. The introduction of signature forgery as a fresh attack vector, coupled with the dramatic reduction in computational cost, challenges long-held assumptions about RSA's resilience in the classical era. The work is seen as an important signal that the timeline for migrating away from RSA may need to be reconsidered, even before quantum computers become viable.