PQC-XXJTLU · cryptanalysis

Home › Public-key schemes

Cryptanalysis of the public-key submissions

Attacks whose cause lies in the specification of a candidate, rated by what they actually cost against what the designers claim and what the call requires.

Implementation vulnerabilities page →

Practical
The construction itself is broken, at a classical cost of at most 280 in the unit of the claim.
Theoretical
The construction itself is broken, below the claim, but the attack is out of reach.
Minor break
A claim falls, but the designers fix it locally (a size, a missing check, a code bug), or only a secondary property falls.
Security proof gap
The security argument does not establish the claim, and no attack is known.

Feasibility. Demonstrated: run on the real parameters. Tested at small scale: run on a smaller instance, the real cost extrapolated. Argued: from an argument or an exact computation.

26 breaks: 4 practical, 0 theoretical, 22 minor; 3 demonstrated. 7 security proof gaps.

Practical (4)

VerdictCandidateFindingFeasibilityCredit
PracticalOrigamiSignature · multivariateUniversal forgery from the public keyDemonstratedPQC-X
PracticalPolar-KEMKEM · latticeNo trapdoor in specificationDemonstratedPQC-X · first public: M.-J. Saarinen
PracticalFacto-DSASignature · multivariateKey recoveryTested at small scalePQC-X · first public: Kris Kwiatkowski
PracticalMAMBA-NIKEKEX · latticeReused static key recoveredTested at small scalePQC-X

Minor break (22)

VerdictCandidateFindingFeasibilityCredit
Minor breakOAEP-NTRUKEM · latticeMalleable ciphertext byte encodingDemonstratedPQC-X
Minor breakCEDRUS+CSignature · hash-basedForgery against a verifier that follows the specificationArguedPQC-X, after Mikhail Kudinov
Minor breakFlexTreeSignature · hash-basedForgery against a verifier that follows the specificationArguedMikhail Kudinov · reproduced by PQC-X
Minor breakBiTSignature · latticeMessage digest too shortTested at small scalePQC-X · first public: M.-J. Saarinen
Minor breakCOMPASS-KEMKEM · latticeSeed, message and key too shortTested at small scalePQC-X* · first public: M.-J. Saarinen*PQC-X adds: message recovery, quantum shortfall
Minor breakMAMBA-ViperKEM · latticeFO coin too shortTested at small scalePQC-X
Minor breakAigis-Sig+Signature · latticeMessage digest too shortArguedPQC-X
Minor breakCOMPASS-SIGSignature · latticeMessage digest too shortArguedPQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall
Minor breakCTLKEM · latticeKey-generation seed too shortArguedPQC-X · first public: M.-J. Saarinen
Minor breakDARTSSignature · latticeMessage digest too shortArguedPQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall
Minor breakFacto-DSASignature · multivariateMessage digest too shortArguedPQC-X
Minor breakLoreKEM · latticeKey seed too shortArguedPQC-X
Minor breakLoreKEM · latticeShared key too shortArguedPQC-X
Minor breakMAMBA-NIKEKEX · latticeSecret seed too shortArguedPQC-X* · first public: M.-J. Saarinen*PQC-X adds: specified seed, passive claim too
Minor breakMORNING-ATLASSignature · latticeUndersized challenge spaceArguedPQC-X
Minor breakMORNING-ATLASSignature · latticeMessage digest too shortArguedPQC-X
Minor breakMORNING-ATLASSignature · latticeUndersized master seedArguedPQC-X
Minor breakOrigamiSignature · multivariateMessage digest too shortArguedPQC-X · first public: M.-J. Saarinen
Minor breakRhymeSignature · latticeKey recovery below levelArguedPQC-X · first public: M.-J. Saarinen
Minor breakRhymeSignature · latticeDigest collision forgeryArguedPQC-X · first public: M.-J. Saarinen
Minor breakTinsSignature · multivariateQuantum security below the call's floorArguedPQC-X
Minor breakTSUOVSignature · multivariateMessage digest too shortArguedPQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall

Security proof gap (7)

VerdictCandidateFindingFeasibilityCredit
Security proof gapNEVKEM · latticeC2 failure rate underestimatedDemonstratedPQC-X
Security proof gapAmoebaKEM · latticeDecryption failure rate understatedArguedPQC-X · first public: Yijian Liu
Security proof gapCheetahKEMKEM · latticeDecryption failures far above claimArguedPQC-X
Security proof gapCOMPASS-KEMKEM · latticeDecryption-failure rate understatedArguedPQC-X
Security proof gapDOVESignature · multivariateProof analyses a different algorithmArguedPQC-X · first public: Dariia Porechna
Security proof gapLoongKEMKEM · latticeDecryption failures far above claimArguedPQC-X
Security proof gapMORNING-ScabbardKEM · latticeDecryption failures far above claimArguedPQC-X

75 findings on 43 candidates: 54 by PQC-X and 21 published by other teams, from 14 authors or groups; 33 breaks by the site's rules.

A public finding is cited as its authors published it: the title is theirs and the link leads to their page. Its verdict is PQC-X's, computed by the same rules as for its own findings from what the report states; PQC-X has not reproduced it. 15 public reports that PQC-X reproduced or found independently are listed once, under PQC-X. Other teams' pages last checked on 2026-09-24.

Practical (6)

VerdictCandidateFindingBy
PracticalFacto-DSASignature · multivariateKey recoveryPQC-X · first public: Kris Kwiatkowski
PracticalFacto-DSASignature · multivariateThe public key yields a universal signing trapdoorngcc.dev sign-10-2MingLLuo2026-09-22
PracticalMAMBA-NIKEKEX · latticeReused static key recoveredPQC-X
PracticalOrigamiSignature · multivariateUniversal forgery from the public keyPQC-X
PracticalPolar-KEMKEM · latticeNo trapdoor in specificationPQC-X · first public: M.-J. Saarinen
PracticalTinsSignature · multivariateOne signature reveals the complete signing witnessngcc.dev sign-29-1Tianyuan Xie2026-09-22

Theoretical (2)

VerdictCandidateFindingBy
TheoreticalCSSignature · latticeVerifier challenge-sign blindness enables universal forgeryngcc.dev sign-07-2Kris Kwiatkowski2026-09-21
TheoreticalHEP-QCKEM · codePublic column multiplicities break the EPC-P assumptionngcc.dev kem-17-4Tianyuan Xie2026-09-22

Minor break (25)

VerdictCandidateFindingBy
Minor breakAigis-Sig+Signature · latticeMessage digest too shortPQC-X
Minor breakBiTSignature · latticeMessage digest too shortPQC-X · first public: M.-J. Saarinen
Minor breakCEDRUS+CSignature · hash-basedForgery against a verifier that follows the specificationPQC-X, after Mikhail Kudinov
Minor breakCOMPASS-KEMKEM · latticeSeed, message and key too shortPQC-X* · first public: M.-J. Saarinen*PQC-X adds: message recovery, quantum shortfall
Minor breakCOMPASS-SIGSignature · latticeMessage digest too shortPQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall
Minor breakCTLKEM · latticeKey-generation seed too shortPQC-X · first public: M.-J. Saarinen
Minor breakDARTSSignature · latticeMessage digest too shortPQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall
Minor breakFacto-DSASignature · multivariateMessage digest too shortPQC-X
Minor breakFlexTreeSignature · hash-basedForgery against a verifier that follows the specificationMikhail Kudinov · reproduced by PQC-X
Minor breakHEP-QCKEM · codeHEP-QC-7 has at most 256 bits of key-generation supportngcc.dev kem-17-2Markku-Juhani O. Saarinen2026-09-21
Minor breakLoreKEM · latticeKey seed too shortPQC-X
Minor breakLoreKEM · latticeShared key too shortPQC-X
Minor breakMAMBA-NIKEKEX · latticeSecret seed too shortPQC-X* · first public: M.-J. Saarinen*PQC-X adds: specified seed, passive claim too
Minor breakMAMBA-ViperKEM · latticeFO coin too shortPQC-X
Minor breakMORNING-ATLASSignature · latticeUndersized challenge spacePQC-X
Minor breakMORNING-ATLASSignature · latticeMessage digest too shortPQC-X
Minor breakMORNING-ATLASSignature · latticeUndersized master seedPQC-X
Minor breakNIIKEKEX · isogenyThe raw shared j-invariant is distinguishable from a uniform keyngcc.dev kex-08-1Markku-Juhani O. Saarinen2026-09-23
Minor breakOAEP-NTRUKEM · latticeMalleable ciphertext byte encodingPQC-X
Minor breakOrigamiSignature · multivariateMessage digest too shortPQC-X · first public: M.-J. Saarinen
Minor breakOrigamiSignature · multivariateSignatures expose the hidden-algebra constraint subspacengcc.dev sign-18-2Peigen Li2026-09-22
Minor breakRhymeSignature · latticeKey recovery below levelPQC-X · first public: M.-J. Saarinen
Minor breakRhymeSignature · latticeDigest collision forgeryPQC-X · first public: M.-J. Saarinen
Minor breakTinsSignature · multivariateQuantum security below the call's floorPQC-X
Minor breakTSUOVSignature · multivariateMessage digest too shortPQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall

Security proof gap (10)

VerdictCandidateFindingBy
Security proof gapAmoebaKEM · latticeDecryption failure rate understatedPQC-X · first public: Yijian Liu
Security proof gapCheetahKEMKEM · latticeDecryption failures far above claimPQC-X
Security proof gapCOMPASS-KEMKEM · latticeDecryption-failure rate understatedPQC-X
Security proof gapDOVESignature · multivariateProof analyses a different algorithmPQC-X · first public: Dariia Porechna
Security proof gapLoongKEMKEM · latticeDecryption failures far above claimPQC-X
Security proof gapMORNING-ScabbardKEM · latticeDecryption failures far above claimPQC-X
Security proof gapNEVKEM · latticeC2 failure rate underestimatedPQC-X
Security proof gapOctarineSignature · latticeThe stated hash requirement is too weak for the EUF-CMA targetngcc.dev sign-16-1Markku-Juhani O. Saarinen2026-09-23
Security proof gapOctarineSignature · latticePolynomial solutions of the relaxed Octarine-512 SIS estimatesngcc.dev sign-16-2Mounir IDRASSI2026-09-23
Security proof gapVDOOSignature · multivariateThe VDOO-256 and -512 proof bound contains a 128-bit salt termngcc.dev sign-33-3Markku-Juhani O. Saarinen2026-09-21

Observations (32)

No claimed or required property falls, or the report establishes nothing yet; a limit of the placeholder hash is marked "not counted".

CandidateFindingBy
BW-KEMKEM · latticeFailure rate averaged over keysPQC-X
CheetahKEMKEM · latticeRing factorization weakens key recoveryPQC-X · first public: XuHaomeng
COMPASS-KEMKEM · latticeCOMPASS-KEM-384 sits at or below 384 bits in the dual and MATZOV cost modelsPQC-X
CreTAKEKEX · latticeBiT-512's digest collision does not transfer into CreTAKE: every signer adds at least 512 fresh bits to what it signsPQC-X
CSSignature · latticeCS-512 sits at its level: primal 7 bits above, contested dual-hybrid 10 to 25 bits belowPQC-X
CSSignature · latticeThe one-bit approximation-loss bound is proven for 264 signatures, not the call's 280PQC-X
CTLKEM · latticeDecryption failures are 51 to 246 bits more likely than claimedPQC-X
DOVESignature · multivariateDOVE-128 meets its level with no marginPQC-X
DOVESignature · multivariateDOVE (sign-09): unsalted SM3 target gives EU-CMA forgery in O(2^128) for DOVE-256 and DOVE-512 not countedngcc-harness issue 9Dariia Porechna2026-09-22
Facto-DSASignature · multivariateA polynomial-time key recovery attack on Facto-DSAePrint 2026/1403Simon Abelard, Ludovic Perret, Hao Shi2026-07-09
FlexTreeSignature · hash-basedThe subset counter re-rolls subsets on a fixed few-time instanceMikhail Kudinov · reproduced by PQC-X**PQC-X adds: the correct budget, no level falls
FlexTreeSignature · hash-basedUnread padding makes signatures malleablePQC-X · first public: Mikhail Kudinov
FlexTreeSignature · hash-basedThe specified PORS tree reuses leaf hash addressesMikhail Kudinov · reproduced by PQC-X
FlexTreeSignature · hash-basedSM3's 256-bit state caps the 384- and 512-bit sets not countedMikhail Kudinov
FlexTreeSignature · hash-basedWithdrawn — SM3 evaluation-mode length extension not countedngcc.dev sign-11-2Mikhail Kudinov2026-09-22
FLITKEM · latticeFailure rate above the claimPQC-X
FLITKEM · latticeBelow 128 in core-SVP onlyPQC-X
LoomKEX · latticeThe specified decryption-failure rate causes honest-session abortsngcc.dev kex-05-1Markku-Juhani O. Saarinen2026-09-21
LoreKEM · latticeLore-512's reducible ring admits smaller quotient attacksngcc.dev kem-19-1Xu Haomeng and collaborators2026-09-23
MAMBA-FrostKEM · latticeEvery Frost profile clears its level in the MATZOV model only; in core-SVP all five are below itPQC-X
MithrilKEM · latticeReversed decryption offset invalidates the failure estimatengcc.dev kem-22-1Samuel J. G. G.2026-09-23
NEVKEM · latticeMessage-dependent decapsulation timingPQC-X
OAEP-NTRUKEM · latticeHonest ciphertexts are distinguishable from uniform byte stringsPQC-X
PhoenixSignature · hash-basedSecurity just below the category at 264 signaturesPQC-X
SQIsign2D-push1/2Signature · isogenyPrime sizing assumes a superseded square-root isogeny costngcc.dev sign-26-1Yintong Luo2026-09-23
SQIsign2D2Signature · isogenyIsogeny prime sizing relies on the former square-root attack costngcc.dev sign-25-2Further extension to Yintong Luo's analysis ; underlying algorithm by Benjamin Wesolowski2026-09-23
SQIsignTriangleSignature · isogenyTriangle prime sizing relies on the former square-root attack costngcc.dev sign-27-2Yintong Luo ; underlying algorithm by Benjamin Wesolowski2026-09-23
TRIKEKEM · codeThe specified TRIKE decoder rejects every tested honest ciphertextngcc.dev kem-36-1Markku-Juhani O. Saarinen2026-09-21
VDOOSignature · multivariateWhether VDOO-512 meets its level depends on the linear-algebra constantPQC-X
VDOOSignature · multivariatePublic comment on VDOO: the level-5 set estimated at 379 bitsPKC forumPeigen Li2026-09-22
YuanYang.KEMKEM · latticeFailure rate underestimatedPQC-X
ZENKEM · latticeKey recovery margin gone at ZEN-512PQC-X

Where other teams publish

SourceByWhat it covers
ngcc.dev reportsM.-J. SaarinenA tracker of reported vulnerabilities in all 119 candidates, collected from several teams, with reproduction steps
CryptHash public comment forumICCSPublic comments on the hash candidates: analyses by ISCAS and the Tsinghua Hash Lab, and the design teams' replies and errata
NGCC PKC public comment forumICCSPublic comments on the public-key candidates, with the design teams' replies and fixes
ngcc-harness issuesGitHubReports and reproduction code submitted to the ngcc.dev tracker
ePrint 2026/2152Y. Yuan, R. Wu, S. Wei, J. Shen, J. Liu, Y. Zhang (ISCAS, UCAS)Structural weaknesses in seven of the hash candidates, among them MoFang, Neulaser, CHIME and CHAMP
ePrint 2026/1403S. Abelard, L. Perret, H. ShiA polynomial-time key recovery on an earlier version of Facto-DSA
champ-cryptanalysisM. IdrassiA collision search on CHAMP, with certificates on reduced parameters
facto_dsa_ngcc_round1MingLLuoA forgery on Facto-DSA-128 from the public key alone