PQC-XXJTLU · cryptanalysis

HomeHash functions › Implementation

Implementation bugs in the hash function submissions

Bugs in the code the designers submitted, where the specification itself is sound. A code bug is fixed in the code, so its verdict is always a minor break. PQC-X does not hunt for these; they are the ones met while attacking the designs.

Cryptanalysis page →

Vulnerabilities (2)

VerdictCandidateFindingFeasibilityCredit
Minor breakEijenHash · symmetricTrivial collisions from the paddingDemonstratedPQC-X · first public: M.-J. Saarinen
Minor breakMasterCubeHash · symmetricTrivial collisions from the paddingDemonstratedPQC-X · first public: M.-J. Saarinen

Observations (2)

Code or test vectors that disagree with the specification, or code that misbehaves, with no claimed property falling.

CandidateFindingFeasibilityCredit
FEILIANHash · symmetricDigest depends on stray bitsDemonstratedPQC-X
uHashHash · symmetricDigest depends on stray bitsDemonstratedPQC-X

20 findings on 15 candidates: 4 by PQC-X and 16 published by other teams, from 3 authors or groups; 2 breaks by the site's rules.

A public finding is cited as its authors published it: the title is theirs and the link leads to their page. Its verdict is PQC-X's, computed by the same rules as for its own findings from what the report states; PQC-X has not reproduced it. 2 public reports that PQC-X reproduced or found independently are listed once, under PQC-X. Other teams' pages last checked on 2026-09-24.

Minor break (2)

VerdictCandidateFindingBy
Minor breakEijenHash · symmetricTrivial collisions from the paddingPQC-X · first public: M.-J. Saarinen
Minor breakMasterCubeHash · symmetricTrivial collisions from the paddingPQC-X · first public: M.-J. Saarinen

Observations (18)

No claimed or required property falls, or the report establishes nothing yet; a limit of the placeholder hash is marked "not counted".

CandidateFindingBy
AFS-TrEDMHash · symmetricPartial-message bits control a machine branchngcc.dev hash-01-1Markku-Juhani O. Saarinen2026-09-23
AXISHash · symmetricAllocation failure returns a successful all-zero digestngcc.dev hash-02-1Markku-Juhani O. Saarinen2026-09-23
AXISHash · symmetricPartial-bit AXIS update branches on secret statengcc.dev hash-02-2Markku-Juhani O. Saarinen2026-09-23
CHAMPHash · symmetricUnsupported digest lengths cause full-size writesngcc.dev hash-04-4Mounir IDRASSI2026-09-22
CHAMPHash · symmetricMessage bytes index a large precomputed matrix tablengcc.dev hash-04-5Markku-Juhani O. Saarinen2026-09-23
FEILIANHash · symmetricDigest depends on stray bitsPQC-X
FEILIANHash · symmetricPadding-allocation failure returns a successful all-zero digestngcc.dev hash-10-1Markku-Juhani O. Saarinen2026-09-23
GarnetHash · symmetricSecret state indexes AES T-tablesngcc.dev hash-11-1Markku-Juhani O. Saarinen2026-09-23
JuziHashHash · symmetricPublic comment on JuziHash: the state-correspondence formula and the MDS description contradict the codeCryptHash forumCryptanalysts001 (ISCAS)2026-09-22
MOZIHash · symmetricPublic comment on MOZI: the printed matrix and Algorithm 4 differ by a transposeCryptHash forumCryptanalysts001 (ISCAS)2026-09-22
NeulaserHash · symmetricSecret state indexes a 256-byte S-boxngcc.dev hash-21-3Markku-Juhani O. Saarinen2026-09-23
PavelorHash · symmetricSecret state indexes AES S-box; tail bits branchngcc.dev hash-22-1Markku-Juhani O. Saarinen2026-09-23
TaiChiHash · symmetricAllocation failure reports success without writing a digestngcc.dev hash-25-1Markku-Juhani O. Saarinen2026-09-23
uHashHash · symmetricDigest depends on stray bitsPQC-X
uHashHash · symmetricSecret state indexes a 256-byte substitution tablengcc.dev hash-05-1Markku-Juhani O. Saarinen2026-09-23
VedakHash · symmetricSecret state indexes an eight-bit substitution tablengcc.dev hash-27-1Markku-Juhani O. Saarinen2026-09-23
WishHash · symmetricPublic comment on Wish: the final-block marker differs between the pseudocode and the text, code and test vectorsCryptHash forumCryptanalysts001 (ISCAS)2026-09-22
WishHash · symmetricSecret-indexed S-box and variable-time field multiplicationngcc.dev hash-35-1Markku-Juhani O. Saarinen2026-09-23

Where other teams publish

SourceByWhat it covers
ngcc.dev reportsM.-J. SaarinenA tracker of reported vulnerabilities in all 119 candidates, collected from several teams, with reproduction steps
CryptHash public comment forumICCSPublic comments on the hash candidates: analyses by ISCAS and the Tsinghua Hash Lab, and the design teams' replies and errata
NGCC PKC public comment forumICCSPublic comments on the public-key candidates, with the design teams' replies and fixes
ngcc-harness issuesGitHubReports and reproduction code submitted to the ngcc.dev tracker
ePrint 2026/2152Y. Yuan, R. Wu, S. Wei, J. Shen, J. Liu, Y. Zhang (ISCAS, UCAS)Structural weaknesses in seven of the hash candidates, among them MoFang, Neulaser, CHIME and CHAMP
ePrint 2026/1403S. Abelard, L. Perret, H. ShiA polynomial-time key recovery on an earlier version of Facto-DSA
champ-cryptanalysisM. IdrassiA collision search on CHAMP, with certificates on reduced parameters
facto_dsa_ngcc_round1MingLLuoA forgery on Facto-DSA-128 from the public key alone