Bugs in the code the designers submitted, where the specification itself is sound. A code bug is fixed in the code, so its verdict is always a minor break. PQC-X does not hunt for these; they are the ones met while attacking the designs.
Vulnerabilities (2)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Minor break | Eijen | Trivial collisions from the padding | Demonstrated | PQC-X · first public: M.-J. Saarinen |
| Minor break | MasterCube | Trivial collisions from the padding | Demonstrated | PQC-X · first public: M.-J. Saarinen |
Observations (2)
Code or test vectors that disagree with the specification, or code that misbehaves, with no claimed property falling.
| Candidate | Finding | Feasibility | Credit |
|---|---|---|---|
| FEILIAN | Digest depends on stray bits | Demonstrated | PQC-X |
| uHash | Digest depends on stray bits | Demonstrated | PQC-X |
20 findings on 15 candidates: 4 by PQC-X and 16 published by other teams, from 3 authors or groups; 2 breaks by the site's rules.
A public finding is cited as its authors published it: the title is theirs and the link leads to their page. Its verdict is PQC-X's, computed by the same rules as for its own findings from what the report states; PQC-X has not reproduced it. 2 public reports that PQC-X reproduced or found independently are listed once, under PQC-X. Other teams' pages last checked on 2026-09-24.
Minor break (2)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Minor break | Eijen | Trivial collisions from the padding | PQC-X · first public: M.-J. Saarinen |
| Minor break | MasterCube | Trivial collisions from the padding | PQC-X · first public: M.-J. Saarinen |
Observations (18)
No claimed or required property falls, or the report establishes nothing yet; a limit of the placeholder hash is marked "not counted".
Where other teams publish
| Source | By | What it covers |
|---|---|---|
| ngcc.dev reports | M.-J. Saarinen | A tracker of reported vulnerabilities in all 119 candidates, collected from several teams, with reproduction steps |
| CryptHash public comment forum | ICCS | Public comments on the hash candidates: analyses by ISCAS and the Tsinghua Hash Lab, and the design teams' replies and errata |
| NGCC PKC public comment forum | ICCS | Public comments on the public-key candidates, with the design teams' replies and fixes |
| ngcc-harness issues | GitHub | Reports and reproduction code submitted to the ngcc.dev tracker |
| ePrint 2026/2152 | Y. Yuan, R. Wu, S. Wei, J. Shen, J. Liu, Y. Zhang (ISCAS, UCAS) | Structural weaknesses in seven of the hash candidates, among them MoFang, Neulaser, CHIME and CHAMP |
| ePrint 2026/1403 | S. Abelard, L. Perret, H. Shi | A polynomial-time key recovery on an earlier version of Facto-DSA |
| champ-cryptanalysis | M. Idrassi | A collision search on CHAMP, with certificates on reduced parameters |
| facto_dsa_ngcc_round1 | MingLLuo | A forgery on Facto-DSA-128 from the public key alone |