--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/20febba1-2c24-4da4-a46e-100b66cfdf47n%40list.nist.gov.
Hi All,
Cool stuff.
Not targeted at anyone in particular -- some thoughts and a totally tangential AI cryptanalysis research note.
First, I would encourage practitioners of AI-assisted cryptanalysis always to provide tangible evidence, such as machine-checkable proofs or successful attack demonstrations against scaled-down versions of targets (like Anthropic did). Anything that makes independent validation easier.
Just as AI helps significantly increase code quality & security if used right (more tests, rigorous formal models, etc.), it can also increase positive assurance of (surviving) crypto algorithms themselves: better proofs, research depth, etc. For example, I'd think that expectation in near future is that more complex security proofs and arguments are machine-checkable. Some additional groundwork may be needed for that with Lean and other tools, though.
ps. Here are some (as far as I know) new McEliece structural key recovery records, including a break of TII-252: https://github.com/mjosaarinen/tii-solved
These were solved with HOVER, a new AI-extended version of the Hemmert-Wiemers HOV attack (Crypto 2026).
--
--
Sincerely,
Demi Marie Obenour (she/her/hers)
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/fe52296c-2366-484e-8ccb-b30ec32eaf56%40gmail.com.
Dear Colleagues,
This is a historic moment in cryptology: AI has beaten humans at cryptanalysis. We would like to share a few thoughts with the PQC community based on our own experience.
There are other dimension-reduction attacks on HAWK in literature. At Eurocrypt 2026, we proposed a dimension-halving algorithm for quaternion Ideal-SVP, which potentially implies that HAWK-n key recovery can be reduced to (cyclotomic) Ideal-SVP in dimension n:
https://eprint.iacr.org/2025/1448
Later, we proposed another guessing attack based on advanced number theory, under a few heuristic assumptions:
https://eprint.iacr.org/2026/1318
However, one of these heuristics was soon found to be invalid by colleagues with the assistance of AI.
Apparently, we were outpaced by AI in both cases. A couple of lessons we have learned are: (a) humans can make mistakes; and (b) humans are slower than AI. Beyond cryptanalysis itself, the use of AI to check mathematical proofs is becoming an increasingly serious issue.
One can even imagine a crisis in cryptography: in the worst-case scenario, all human-designed cryptosystems are broken by AI. Whether or not that happens, a new era—Post-AI Cryptography—has arrived.
Cong Ling
Will the SQIsign Team now withdraw their candidate from the process on similar grounds because of https://eprint.iacr.org/2026/1486.pdf?
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/275cd2b0-becb-45e4-83cf-beac6be59dadn%40list.nist.gov.
Natalia D'Onofrio, FRP, MBA
Affinity Ventures, LLC | Founder
P.O. Box 2059
Palm Beach, FL 33480
Tel: (561) 501-1033
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/85aedddd-2446-4f03-bdc6-34d6149f70fcn%40list.nist.gov.
I agree Cong !
Best Regards,
Dr. Shravani Shahapure, CISSP
PhD (Electronics Engineering Specialization in Cryptology)
Quantum Safe Cyber security, Cryptography Specialist
sshah...@deloitte.com | www.deloitte.com
From: pqc-...@list.nist.gov <pqc-...@list.nist.gov>
On Behalf Of Natalia
Sent: Friday, July 31, 2026 8:15 AM
To: Cong Ling <cli...@googlemail.com>
Cc: pqc-forum <pqc-...@list.nist.gov>; dustin...@nist.gov <dustin...@nist.gov>; leo.d...@gmail.com <leo.d...@gmail.com>; sw...@anthropic.com <sw...@anthropic.com>
Subject: [EXT] Re: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
|
You don't often get email from nataliascor...@gmail.com. Learn why this is important |
Cong,
I agree with you. I was a bit blown away by the news, but I hate to say that I'm not surprised. Maybe we need a path forward that is not so linear or multiple paths. We can't think like we did before. We need more 4D and 5D thinking.
This loss is unexpected. Thank you Hawk for your contributions.
Natalia D'Onofrio, FRP, MBA
Affinity Ventures, LLC | Founder
P.O. Box 2059
Palm Beach, FL 33480
Tel: (561) 501-1033
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/CAMux9nCwhiTtBhSb7Tq3Li7goDN4kRYFtpgSGeMT%2BivzCVeiJA%40mail.gmail.com.
This message (including any attachment(s) hereto) is confidential and is intended solely for the use of the individual or the entity to whom they are addressed. In the event, you are not the intended recipient and have received this message in error or
inadvertently, you are hereby notified that retaining, disclosing, reproducing, distributing, printing, or taking any action by relying on the contents of the information is strictly prohibited and you are requested to forthwith delete this message without
retaining any copy or part thereof. When addressed to our clients, any opinions or advice contained in this email are subject to the terms and conditions expressed in the governing client engagement letter. Any action or omission in contravention of the foregoing
requirement may be construed to be against the applicable laws and may have legal consequences. We do not accept any responsibility and are not liable for any incorrect transmission of this message nor for any losses sustained because of this message.
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/85aedddd-2446-4f03-bdc6-34d6149f70fcn%40list.nist.gov.
--
You received this message because you are subscribed to the Google Groups "pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pqc-forum+...@list.nist.gov.
To view this discussion visit https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/09f45a33-bf7c-42cd-956d-ad4fecaccf3cn%40list.nist.gov.