The SQIsign team would like to bring your attention to
https://ia.cr/2026/1486, where a new attack against the supersingular isogeny / endomorphism ring problem with better asymptotic complexity than all previously known algorithms is presented. We have no reason to doubt the correctness of the attack, and in fact we have validated it experimentally on toy parameters.
The new attack is still exponential-time: the complexity improves from Õ(p¹ᐟ²) to p¹ᐟ³⁺ᵒ⁽¹⁾, or to Õ(p¹ᐟ³) by a slight extension of the approach of this paper. Thus, it does not compromise SQIsign's participation to the selection process, but it will require careful re-consideration of the parameters. The team is hard at work analyzing the scope and practical impact of this new technique and will deliver its provisional conclusions in the next revision of the specification document, due August 14.
Until then, the team has decided to refrain from publicly commenting on how the attack will impact SQIsign. We invite the community to share their insights in this email thread, or privately at
con...@sqisign.org.
Décio, on behalf of the SQIsign team