Breaking RSA with Wiener's Attack
Small private exponents make RSA decryption and signing faster. Michael Wiener showed in 1990 that a d small enough to help performance is also small enough to recover from the public key alone, via continued fractions.