<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky" -->

---
title: There’s a new way to break RSA that’s faster than...
description: Cryptographers led by Nadia Heninger have developed a new attack that forges RSA digital signatures without factoring the private key, previously believed to...
canonical: https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: There’s a new way to break RSA that’s faster than anything we’ve seen before | daily.dev
og:description: Cryptographers led by Nadia Heninger have developed a new attack that forges RSA digital signatures without factoring the private key, previously believed to...
og:url: https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky
og:image: https://api.daily.dev/og/posts/y5WVVP2KY.png
og:image:alt: There’s a new way to break RSA that’s faster than anything we’ve seen before
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# There’s a new way to break RSA that’s faster than anything we’ve seen before

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 3 min read · 0 upvotes · 0 comments

## Summary

Cryptographers led by Nadia Heninger have developed a new attack that forges RSA digital signatures without factoring the private key, previously believed to be the only path to breaking RSA. The method drastically reduces the computational resources needed compared to factoring, though 2048-bit and larger keys remain out of practical reach for now. Even 1024-bit RSA, already deprecated, still requires resources beyond most attackers except nation-states or large companies. The paper is undergoing peer review, and experts like Karsten Nohl call it a potential conceptual breakthrough if it holds up.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before>

## Questions this post answers

### Is RSA broken by this new signature forgery attack?

Not in practice yet. The attack, developed by Nadia Heninger and collaborators, forges RSA signatures without factoring the private key, but it still requires more computation than nearly anyone besides nation-states or large tech companies can muster, even against deprecated 1024-bit keys. Widely used RSA implementations remain safe, and 2048-bit and 4096-bit keys are far less affected, though their theoretical security margin is reduced.

_Track how emerging cryptographic attacks affect RSA key sizes you rely on with daily.dev._

### How much computation was previously needed to break 1024-bit RSA by factoring?

Breaking 1024-bit RSA by factoring the private key was estimated to cost on the order of tens of millions of dollars in computation time for a single key, feasible mainly for large tech companies or agencies like the NSA. For 2048-bit RSA, factoring was considered completely out of reach. The new signature forgery method reduces the resources required by orders of magnitude compared to factoring.

_Developers weighing RSA key sizes against attack cost estimates can follow updates on daily.dev._

## Similar posts on daily.dev

- [Schneier on Security](https://daily.dev/posts/schneier-on-security-uak0g9tjb) · Schneier on Security · 0 upvotes · 0 comments
- [Schneier on Security](https://daily.dev/posts/schneier-on-security-mpktnmwvf) · Schneier on Security · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cryptography](https://daily.dev/tags/cryptography)

[View this post on daily.dev](https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"There’s a new way to break RSA that’s faster than anything we’ve seen before","url":"https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky"},"datePublished":"2026-09-24T12:39:44.759Z","dateModified":"2026-09-24T12:40:07.948Z","description":"Cryptographers led by Nadia Heninger have developed a new attack that forges RSA digital signatures without factoring the private key, previously believed to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bcd478156c8bcb4c9f86f0b3cc9ad5d7?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bcd478156c8bcb4c9f86f0b3cc9ad5d7?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cryptography","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"There’s a new way to break RSA that’s faster than anything we’ve seen before"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/there-s-a-new-way-to-break-rsa-that-s-faster-than-anything-we-ve-seen-before-y5wvvp2ky#faq","mainEntity":[{"@type":"Question","name":"Is RSA broken by this new signature forgery attack?","acceptedAnswer":{"@type":"Answer","text":"Not in practice yet. The attack, developed by Nadia Heninger and collaborators, forges RSA signatures without factoring the private key, but it still requires more computation than nearly anyone besides nation-states or large tech companies can muster, even against deprecated 1024-bit keys. Widely used RSA implementations remain safe, and 2048-bit and 4096-bit keys are far less affected, though their theoretical security margin is reduced. Track how emerging cryptographic attacks affect RSA key sizes you rely on with daily.dev."}},{"@type":"Question","name":"How much computation was previously needed to break 1024-bit RSA by factoring?","acceptedAnswer":{"@type":"Answer","text":"Breaking 1024-bit RSA by factoring the private key was estimated to cost on the order of tens of millions of dollars in computation time for a single key, feasible mainly for large tech companies or agencies like the NSA. For 2048-bit RSA, factoring was considered completely out of reach. The new signature forgery method reduces the resources required by orders of magnitude compared to factoring. Developers weighing RSA key sizes against attack cost estimates can follow updates on daily.dev."}}]}
```

