A man on his own, at home, armed with calculations and patience, manages to do what the greatest French banks deemed impossible: break the mathematical lock meant to protect all of the country’s bank cards. It isn’t a police operation, nor an internal bank audit, nor a hacker seeking to profit who uncovers this glaring flaw. It is the author himself who, attempting to sell it legally, ends up turning himself in and finds himself trapped by the very people he thought he was helping. A look back at an affair as improbable as it is revealing, that of Serge Humpich, the engineer who made the French banking system tremble at the end of the 1990s.
- Serge Humpich, a lone engineer, factored the 320-bit RSA key protecting French bank cards and demonstrated the flaw by purchasing metro tickets with a forged card.
- After attempting to sell his discovery to the Groupement des Cartes Bancaires so that it could be fixed, he was trapped during a meeting and prosecuted, receiving ten months’ suspended prison time and a 12,000-franc fine.
- Following this affair, RSA keys moved from 320 to 768 bits, but the underlying logical flaw was not fully corrected until May 2007.
- The flaw no one should have found
- The fake card that should never have existed
- The trap set by those he wished to alert
- What this case changed for banking security
The flaw no one should have found
At the end of the 1990s, the security of credit transactions in France relied on an asymmetric encryption system called RSA, secured by a 320-bit key. That length, today trivial in the face of current computing power, was then regarded by industry experts as robust enough to deter any hacking attempt. The paradox is that as early as 1988, a decade earlier, cryptography specialists had already warned against the use of such a short key, deeming it fragile in the long term.
Into this setting steps Serge Humpich, an electronic engineer with a passion for cryptography, who decides to take on the problem alone, without the industrial resources of a laboratory or a specialist company. His approach is not a premeditated hacking operation: it is first and foremost a mental challenge, the desire to verify whether the much-touted security of the French banking system could withstand the test of mathematics. After several months of relentless calculations, conducted from his home, he achieves the improbable: he factorizes the RSA key and obtains the corresponding private key, the very key that would allow any French bank card to be authenticated as perfectly legitimate.
The fake card that should never have existed
Armed with this key, Serge Humpich creates what would later be called Yes Cards: modified smart cards that accept any secret code entered by the user, never rejecting it. To prove that his discovery actually works in practice, not just on paper, he chooses a testing ground as symbolic as it is accessible: Paris’s metro ticket machines. He buys ten booklets with his counterfeit cards, keeping the tickets and vouchers as tangible proof of his success.
The transaction goes through without a hitch. The financial system, supposed to detect any anomaly, accepts the card as perfectly legitimate. This demonstration confirms what Humpich suspected: the flaw is not theoretical, it is fully exploitable in real conditions. Rather than profiting from this discovery through fraud, he chooses a path he believes is responsible and honest: to contact directly the Groupement des Cartes Bancaires, through a lawyer, to propose a transfer of knowledge, in other words to sell the information so that the flaw can be fixed before it falls into the wrong hands.
The trap set by those he wished to alert
Convinced that he was acting in the public interest, Serge Humpich offered his know-how in exchange for compensation. But the Groupement des Cartes Bancaires, far from treating this as a service rendered, demanded first concrete evidence of his ability to mislead payment terminals, which explains the demonstration conducted in the Paris metro. A meeting was then arranged, officially to negotiate the terms of this transfer of skills. In reality, this meeting turned out to be a genuine ambush: on 4 August 1998, the GIE Cartes Bancaires filed a complaint for intrusion into an automated data-processing system and counterfeiting of bank cards.
The law firm representing the banking group would even go so far as to characterize Humpich’s approach as an attempt at extortion, likening it to a mafioso-style shakedown. A year and a half later, the trial opened before the 13th chamber of the Paris criminal court. In front of the judges stood a 35-year-old electrical engineer, the first man to have managed to breach the security system of France’s smart cards. His trial became the symbol of a lingering legal ambiguity surrounding security research: the boundary between a whistleblower acting with good intentions and a cybercriminal is dangerously thin in the French law of the time. The verdict followed soon after: ten months of suspended prison time, a 12,000-franc fine, and a symbolic one-franc damage claim paid to the Groupement des Cartes Bancaires.
What this case changed for banking security
Humpich’s case illustrates a paradox that remains at the heart of cybersecurity debates today: the person who reveals a vulnerability in good faith can be punished more severely than the one who would exploit it quietly, for genuinely criminal purposes. Humpich was convicted despite the absence of any real financial harm to banks or users. This imbalance between intention and punishment continues to fuel reflection on the need for a clear legal framework for the responsible disclosure of computer vulnerabilities.
On the technical side, the affair nevertheless pushed the Groupement des Cartes Bancaires to react. The old 320-bit keys were gradually replaced by 768-bit keys, far more resistant to the computing power available at the time. It would, however, take until May 2007, nearly a decade after Humpich’s discovery, for the underlying logical flaw to be completely fixed. Since this watershed episode, it has been certain that RSA keys can be broken, and this case is still cited today as a milestone in the history of applied cryptography and the security of card payments in France.
More than two decades after the events, Serge Humpich’s story continues to question how our society treats security researchers who, often alone and with limited means, uncover critical flaws in systems believed to be inviolable. Between deserved recognition and legal prosecution, the fate of these technological whistleblowers remains an open question. And if the real flaw of this affair was not solely mathematical, but also legal and human?