Attacks whose cause lies in the specification of a candidate, rated by what they actually cost against what the designers claim and what the call requires.
Implementation vulnerabilities page →
- Practical
- The construction itself is broken, at a classical cost of at most 280 in the unit of the claim.
- Theoretical
- The construction itself is broken, below the claim, but the attack is out of reach.
- Minor break
- A claim falls, but the designers fix it locally (a size, a missing check, a code bug), or only a secondary property falls.
- Security proof gap
- The security argument does not establish the claim, and no attack is known.
Feasibility. Demonstrated: run on the real parameters. Tested at small scale: run on a smaller instance, the real cost extrapolated. Argued: from an argument or an exact computation.
10 breaks: 4 practical, 2 theoretical, 4 minor; 4 demonstrated. 1 security proof gap.
Practical (4)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Practical | MoFang | Collisions and second preimages, at no cost | Demonstrated | PQC-X · first public: Cryptanalysts001 (ISCAS) |
| Practical | Neulaser | Collisions and second preimages | Demonstrated | PQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: second preimages |
| Practical | CHAMP | Collisions | Tested at small scale | PQC-X · first public: M.-J. Saarinen |
| Practical | CHIME | Collisions | Tested at small scale | PQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: subset collisions found, tighter bound |
Theoretical (2)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Theoretical | ZC-DM | Collisions | Tested at small scale | PQC-X |
| Theoretical | ZC-DMC | Collisions | Tested at small scale | PQC-X |
Minor break (4)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Minor break | CHAMP | Short inputs recovered from the digest | Demonstrated | PQC-X |
| Minor break | uHash | Length extension | Demonstrated | PQC-X |
| Minor break | AXIS | Second-preimage claim above the generic bound | Argued | PQC-X |
| Minor break | uHash | Second-preimage claim above the generic bound | Argued | PQC-X |
Security proof gap (1)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Security proof gap | MasterCube | Security argument covers neither version | Demonstrated | PQC-X · first public: Cryptanalysts001 (ISCAS) |
38 findings on 18 candidates: 16 by PQC-X and 22 published by other teams, from 8 authors or groups; 19 breaks by the site's rules.
A public finding is cited as its authors published it: the title is theirs and the link leads to their page. Its verdict is PQC-X's, computed by the same rules as for its own findings from what the report states; PQC-X has not reproduced it. 7 public reports that PQC-X reproduced or found independently are listed once, under PQC-X. Other teams' pages last checked on 2026-09-24.
Practical (9)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Practical | CHAMP | Collisions | PQC-X · first public: M.-J. Saarinen |
| Practical | CHIME | Collisions | PQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: subset collisions found, tighter bound |
| Practical | CHIME | Structural Weaknesses in 7 NGCC Submitted Hash Functions | Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang |
| Practical | MoFang | Collisions and second preimages, at no cost | PQC-X · first public: Cryptanalysts001 (ISCAS) |
| Practical | MoFang | Structural Weaknesses in 7 NGCC Submitted Hash Functions | Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang |
| Practical | MoFang | Round-key cancellation gives deterministic full-round collisions | Tsinghua Hash Lab |
| Practical | Neulaser | Collisions and second preimages | PQC-X* · first public: Cryptanalysts001 (ISCAS)*PQC-X adds: second preimages |
| Practical | Neulaser | Structural Weaknesses in 7 NGCC Submitted Hash Functions | Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang |
| Practical | Neulaser | Reduction modulo 2^32-5 creates reachable state mergers | Tsinghua Hash Lab |
Theoretical (3)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Theoretical | CHAMP | Known-length preimages admit an exact square-root search | Mounir IDRASSI |
| Theoretical | ZC-DM | Collisions | PQC-X |
| Theoretical | ZC-DMC | Collisions | PQC-X |
Minor break (7)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Minor break | AXIS | Second-preimage claim above the generic bound | PQC-X |
| Minor break | CHAMP | Short inputs recovered from the digest | PQC-X |
| Minor break | CHAMP | Fixed-length outputs occupy only one determinant fiber | Markku-Juhani O. Saarinen |
| Minor break | CHAMP | Structural Weaknesses in 7 NGCC Submitted Hash Functions | Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang |
| Minor break | MEGASCON | The AVX-512 listing defines a noninjective S-box and practical collisions | Cryptanalysts001 (ISCAS) |
| Minor break | uHash | Length extension | PQC-X |
| Minor break | uHash | Second-preimage claim above the generic bound | PQC-X |
Security proof gap (1)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Security proof gap | MasterCube | Security argument covers neither version | PQC-X · first public: Cryptanalysts001 (ISCAS) |
Observations (18)
No claimed or required property falls, or the report establishes nothing yet; a limit of the placeholder hash is marked "not counted".
Where other teams publish
| Source | By | What it covers |
|---|---|---|
| ngcc.dev reports | M.-J. Saarinen | A tracker of reported vulnerabilities in all 119 candidates, collected from several teams, with reproduction steps |
| CryptHash public comment forum | ICCS | Public comments on the hash candidates: analyses by ISCAS and the Tsinghua Hash Lab, and the design teams' replies and errata |
| NGCC PKC public comment forum | ICCS | Public comments on the public-key candidates, with the design teams' replies and fixes |
| ngcc-harness issues | GitHub | Reports and reproduction code submitted to the ngcc.dev tracker |
| ePrint 2026/2152 | Y. Yuan, R. Wu, S. Wei, J. Shen, J. Liu, Y. Zhang (ISCAS, UCAS) | Structural weaknesses in seven of the hash candidates, among them MoFang, Neulaser, CHIME and CHAMP |
| ePrint 2026/1403 | S. Abelard, L. Perret, H. Shi | A polynomial-time key recovery on an earlier version of Facto-DSA |
| champ-cryptanalysis | M. Idrassi | A collision search on CHAMP, with certificates on reduced parameters |
| facto_dsa_ngcc_round1 | MingLLuo | A forgery on Facto-DSA-128 from the public key alone |