PQC-XXJTLU · cryptanalysis

Home › Hash functions

Cryptanalysis of the hash function submissions

Attacks whose cause lies in the specification of a candidate, rated by what they actually cost against what the designers claim and what the call requires.

Implementation vulnerabilities page →

Practical
The construction itself is broken, at a classical cost of at most 280 in the unit of the claim.
Theoretical
The construction itself is broken, below the claim, but the attack is out of reach.
Minor break
A claim falls, but the designers fix it locally (a size, a missing check, a code bug), or only a secondary property falls.
Security proof gap
The security argument does not establish the claim, and no attack is known.

Feasibility. Demonstrated: run on the real parameters. Tested at small scale: run on a smaller instance, the real cost extrapolated. Argued: from an argument or an exact computation.

10 breaks: 4 practical, 2 theoretical, 4 minor; 4 demonstrated. 1 security proof gap.

Practical (4)

VerdictCandidateFindingFeasibilityCredit
PracticalMoFangHash · symmetricCollisions and second preimages, at no costDemonstratedPQC-X · first public: Cryptanalysts001 (ISCAS)
PracticalNeulaserHash · symmetricCollisions and second preimagesDemonstratedPQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: second preimages
PracticalCHAMPHash · symmetricCollisionsTested at small scalePQC-X · first public: M.-J. Saarinen
PracticalCHIMEHash · symmetricCollisionsTested at small scalePQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: subset collisions found, tighter bound

Theoretical (2)

VerdictCandidateFindingFeasibilityCredit
TheoreticalZC-DMHash · symmetricCollisionsTested at small scalePQC-X
TheoreticalZC-DMCHash · symmetricCollisionsTested at small scalePQC-X

Minor break (4)

VerdictCandidateFindingFeasibilityCredit
Minor breakCHAMPHash · symmetricShort inputs recovered from the digestDemonstratedPQC-X
Minor breakuHashHash · symmetricLength extensionDemonstratedPQC-X
Minor breakAXISHash · symmetricSecond-preimage claim above the generic boundArguedPQC-X
Minor breakuHashHash · symmetricSecond-preimage claim above the generic boundArguedPQC-X

Security proof gap (1)

VerdictCandidateFindingFeasibilityCredit
Security proof gapMasterCubeHash · symmetricSecurity argument covers neither versionDemonstratedPQC-X · first public: Cryptanalysts001 (ISCAS)

38 findings on 18 candidates: 16 by PQC-X and 22 published by other teams, from 8 authors or groups; 19 breaks by the site's rules.

A public finding is cited as its authors published it: the title is theirs and the link leads to their page. Its verdict is PQC-X's, computed by the same rules as for its own findings from what the report states; PQC-X has not reproduced it. 7 public reports that PQC-X reproduced or found independently are listed once, under PQC-X. Other teams' pages last checked on 2026-09-24.

Practical (9)

VerdictCandidateFindingBy
PracticalCHAMPHash · symmetricCollisionsPQC-X · first public: M.-J. Saarinen
PracticalCHIMEHash · symmetricCollisionsPQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: subset collisions found, tighter bound
PracticalCHIMEHash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
PracticalMoFangHash · symmetricCollisions and second preimages, at no costPQC-X · first public: Cryptanalysts001 (ISCAS)
PracticalMoFangHash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
PracticalMoFangHash · symmetricRound-key cancellation gives deterministic full-round collisionsngcc.dev hash-19-1Tsinghua Hash Lab2026-09-22
PracticalNeulaserHash · symmetricCollisions and second preimagesPQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: second preimages
PracticalNeulaserHash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
PracticalNeulaserHash · symmetricReduction modulo 2^32-5 creates reachable state mergersngcc.dev hash-21-2Tsinghua Hash Lab2026-09-22

Theoretical (3)

VerdictCandidateFindingBy
TheoreticalCHAMPHash · symmetricKnown-length preimages admit an exact square-root searchngcc.dev hash-04-3Mounir IDRASSI2026-09-22
TheoreticalZC-DMHash · symmetricCollisionsPQC-X
TheoreticalZC-DMCHash · symmetricCollisionsPQC-X

Minor break (7)

VerdictCandidateFindingBy
Minor breakAXISHash · symmetricSecond-preimage claim above the generic boundPQC-X
Minor breakCHAMPHash · symmetricShort inputs recovered from the digestPQC-X
Minor breakCHAMPHash · symmetricFixed-length outputs occupy only one determinant fiberngcc.dev hash-04-1Markku-Juhani O. Saarinen2026-09-21
Minor breakCHAMPHash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
Minor breakMEGASCONHash · symmetricThe AVX-512 listing defines a noninjective S-box and practical collisionsngcc.dev hash-18-2Cryptanalysts001 (ISCAS)2026-09-22
Minor breakuHashHash · symmetricLength extensionPQC-X
Minor breakuHashHash · symmetricSecond-preimage claim above the generic boundPQC-X

Security proof gap (1)

VerdictCandidateFindingBy
Security proof gapMasterCubeHash · symmetricSecurity argument covers neither versionPQC-X · first public: Cryptanalysts001 (ISCAS)

Observations (18)

No claimed or required property falls, or the report establishes nothing yet; a limit of the placeholder hash is marked "not counted".

CandidateFindingBy
CHAMPHash · symmetricPublic comment on CHAMP: commuting matrices and a birthday over projective labelsCryptHash forumTsinghua Hash Lab2026-09-22
CuishenHash · symmetricPublic comment on Cuishen: an invariant subspace of the message expansionCryptHash forumCryptanalysts001 (ISCAS)2026-09-22
CuishenHash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
EijenHash · symmetricEijen-h is the last h bits of a longer Eijen for one-block messagesPQC-X
EijenHash · symmetricCross-instance three-block relationsngcc.dev hash-09-2Tsinghua Hash Lab2026-09-22
IpheHash · symmetricCross-profile 512-bit output relationngcc.dev hash-12-1Iphe Algorithm Group2026-09-23
LaurusHash · symmetricLaurus-XOF and Laurus-512 coincide on 1024 message lengthsPQC-X
LaurusHash · symmetricLaurus loses its function-domain separation at c=1024ngcc.dev hash-14-1Tsinghua Hash Lab2026-09-22
MEGASCONHash · symmetricThe 384-bit digest is a prefix of the 512-bit digest for short messagesPQC-X · first public: M.-J. Saarinen
MoFangHash · symmetricMoFang-768 is MoFang-1024 with its halves swapped and cut, for one-block messagesPQC-X
MOZIHash · symmetricThe 384-bit digest is a prefix of the 512-bit digest for short messagesPQC-X · first public: M.-J. Saarinen
MOZIHash · symmetricThe specified final marker creates cross-rate relations absent from the implementationngcc.dev hash-20-2Tsinghua Hash Lab2026-09-22
QuantaSylva Hash (QSH)Hash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
QuantaSylva Hash (QSH)Hash · symmetricFull-round core permutation has a one-query invariant-subspace distinguisherngcc.dev hash-24-1ISCAS2026-09-22
WChainHash · symmetricPublic comment on WChain: an invariant subspace of the word operationsCryptHash forumCryptanalysts001 (ISCAS)2026-09-22
WChainHash · symmetricStructural Weaknesses in 7 NGCC Submitted Hash FunctionsePrint 2026/2152Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang2026-09-22
ZC-DMCHash · symmetricCross-domain distinguisher between ZC-1536-512 and ZC-1536-768ngcc.dev hash-31-1Tsinghua Hash Lab2026-09-22
ZC-EDMCHash · symmetricThe specified and implemented ZC-EDMC mappings differngcc.dev hash-32-1Cryptanalysts001, Institute of Software, Chinese Academy of Sciences2026-09-22

Where other teams publish

SourceByWhat it covers
ngcc.dev reportsM.-J. SaarinenA tracker of reported vulnerabilities in all 119 candidates, collected from several teams, with reproduction steps
CryptHash public comment forumICCSPublic comments on the hash candidates: analyses by ISCAS and the Tsinghua Hash Lab, and the design teams' replies and errata
NGCC PKC public comment forumICCSPublic comments on the public-key candidates, with the design teams' replies and fixes
ngcc-harness issuesGitHubReports and reproduction code submitted to the ngcc.dev tracker
ePrint 2026/2152Y. Yuan, R. Wu, S. Wei, J. Shen, J. Liu, Y. Zhang (ISCAS, UCAS)Structural weaknesses in seven of the hash candidates, among them MoFang, Neulaser, CHIME and CHAMP
ePrint 2026/1403S. Abelard, L. Perret, H. ShiA polynomial-time key recovery on an earlier version of Facto-DSA
champ-cryptanalysisM. IdrassiA collision search on CHAMP, with certificates on reduced parameters
facto_dsa_ngcc_round1MingLLuoA forgery on Facto-DSA-128 from the public key alone