Fwd: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1

13 views
Skip to first unread message

Ruy Jose Guerra Barretto de Queiroz

unread,
Aug 1, 2026, 10:37:35 AM (11 days ago) Aug 1
to Lista acadêmica brasileira dos profissionais e estudantes da área de LOGICA


---------- Forwarded message ---------
De: 'Cong Ling' via pqc-forum
Date: sáb., 1 de ago. de 2026 às 11:29
Subject: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
To: pqc-forum 


AI has now also surpassed humans in lattice theory... Today, OpenAI announced a new upper bound of 0.604 for the exponent of the sphere-packing density. Improving this upper bound has been a major open problem in lattice theory ever since Kabatiansky and Levenshtein established the previous best exponent of 0.599 in 1978. This is the first improvement in nearly half a century. 
On Wednesday, July 29, 2026 at 4:09:58 PM UTC+1 dustin...@nist.gov wrote:
All,

NIST would like to thank the HAWK team for all the work they've done on their submission throughout the process.  We have updated our Round 3 page for the onramp to indicate that HAWK has been withdrawn:

Dustin Moody
NIST PQC

On Wednesday, July 29, 2026 at 6:02:19 AM UTC-4 leo.d...@gmail.com wrote:
 Dear Steve and pqc-forum,

We would like to thank Anthropic for their contribution to the cryptanalysis of HAWK, and for communicating with us throughout.
We confirm that their attack approximately halves the block size required in lattice reduction to recover (an equivalent) secret key.
Naïve approaches to circumvent this, such as doubling parameters or moving to higher rank modules, make HAWK uncompetitive.
As such, we withdraw our candidate HAWK from NIST's ongoing additional signature scheme standardisation process.

Good luck to all the remaining candidates.
The HAWK team would like to thank everyone who has attacked, contributed to or discussed HAWK since the it's publication in 2022.

-- the HAWK team

Le mardi 28 juillet 2026 à 19:06:14 UTC+2, Steve Weis a écrit :
Hello pqc-forum. We would like to announce an improved key recovery attack against HAWK-n that reduces to SVP in dimension n/2 + 1. The paper will appear at https://anthropic.com/document/hawk_key_recovery.pdf and is linked to from an accompanying blog post that will shortly be live: https://www.anthropic.com/research/discovering-cryptographic-weaknesses

In the gate-count model of AGPS'20, the improved attack lowers the key-recovery cost of HAWK-512 from 2^150 to 2^108 and of HAWK-1024 from 2^288 to 2^182. We demonstrate this with a practical implementation that recovers a HAWK-256 secret key end-to-end in a few hours on a single server. The implementation can be found at: https://github.com/anthropics/cryptography-research-demo

This result does not impact Falcon, ML-DSA, or other latticed-based schemes.

We would like to thank the HAWK team for their help verifying this result and for their feedback. We would also like to acknowledge that this was found by Claude, with minimal technical guidance from people. For more information on the process, please refer to the above blog post.

Thank you very much.

--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/91299e2c-64c2-4f53-978b-7cd1b30cfea4n%40list.nist.gov.
Reply all
Reply to author
Forward
0 new messages