Attacks whose cause lies in the specification of a candidate, rated by what they actually cost against what the designers claim and what the call requires.
Implementation vulnerabilities page →
- Practical
- The construction itself is broken, at a classical cost of at most 280 in the unit of the claim.
- Theoretical
- The construction itself is broken, below the claim, but the attack is out of reach.
- Minor break
- A claim falls, but the designers fix it locally (a size, a missing check, a code bug), or only a secondary property falls.
- Security proof gap
- The security argument does not establish the claim, and no attack is known.
Feasibility. Demonstrated: run on the real parameters. Tested at small scale: run on a smaller instance, the real cost extrapolated. Argued: from an argument or an exact computation.
26 breaks: 4 practical, 0 theoretical, 22 minor; 3 demonstrated. 7 security proof gaps.
Practical (4)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Practical | Origami | Universal forgery from the public key | Demonstrated | PQC-X |
| Practical | Polar-KEM | No trapdoor in specification | Demonstrated | PQC-X · first public: M.-J. Saarinen |
| Practical | Facto-DSA | Key recovery | Tested at small scale | PQC-X · first public: Kris Kwiatkowski |
| Practical | MAMBA-NIKE | Reused static key recovered | Tested at small scale | PQC-X |
Minor break (22)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Minor break | OAEP-NTRU | Malleable ciphertext byte encoding | Demonstrated | PQC-X |
| Minor break | CEDRUS+C | Forgery against a verifier that follows the specification | Argued | PQC-X, after Mikhail Kudinov |
| Minor break | FlexTree | Forgery against a verifier that follows the specification | Argued | Mikhail Kudinov · reproduced by PQC-X |
| Minor break | BiT | Message digest too short | Tested at small scale | PQC-X · first public: M.-J. Saarinen |
| Minor break | COMPASS-KEM | Seed, message and key too short | Tested at small scale | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: message recovery, quantum shortfall |
| Minor break | MAMBA-Viper | FO coin too short | Tested at small scale | PQC-X |
| Minor break | Aigis-Sig+ | Message digest too short | Argued | PQC-X |
| Minor break | COMPASS-SIG | Message digest too short | Argued | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall |
| Minor break | CTL | Key-generation seed too short | Argued | PQC-X · first public: M.-J. Saarinen |
| Minor break | DARTS | Message digest too short | Argued | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall |
| Minor break | Facto-DSA | Message digest too short | Argued | PQC-X |
| Minor break | Lore | Key seed too short | Argued | PQC-X |
| Minor break | Lore | Shared key too short | Argued | PQC-X |
| Minor break | MAMBA-NIKE | Secret seed too short | Argued | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: specified seed, passive claim too |
| Minor break | MORNING-ATLAS | Undersized challenge space | Argued | PQC-X |
| Minor break | MORNING-ATLAS | Message digest too short | Argued | PQC-X |
| Minor break | MORNING-ATLAS | Undersized master seed | Argued | PQC-X |
| Minor break | Origami | Message digest too short | Argued | PQC-X · first public: M.-J. Saarinen |
| Minor break | Rhyme | Key recovery below level | Argued | PQC-X · first public: M.-J. Saarinen |
| Minor break | Rhyme | Digest collision forgery | Argued | PQC-X · first public: M.-J. Saarinen |
| Minor break | Tins | Quantum security below the call's floor | Argued | PQC-X |
| Minor break | TSUOV | Message digest too short | Argued | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall |
Security proof gap (7)
| Verdict | Candidate | Finding | Feasibility | Credit |
|---|---|---|---|---|
| Security proof gap | NEV | C2 failure rate underestimated | Demonstrated | PQC-X |
| Security proof gap | Amoeba | Decryption failure rate understated | Argued | PQC-X · first public: Yijian Liu |
| Security proof gap | CheetahKEM | Decryption failures far above claim | Argued | PQC-X |
| Security proof gap | COMPASS-KEM | Decryption-failure rate understated | Argued | PQC-X |
| Security proof gap | DOVE | Proof analyses a different algorithm | Argued | PQC-X · first public: Dariia Porechna |
| Security proof gap | LoongKEM | Decryption failures far above claim | Argued | PQC-X |
| Security proof gap | MORNING-Scabbard | Decryption failures far above claim | Argued | PQC-X |
75 findings on 43 candidates: 54 by PQC-X and 21 published by other teams, from 14 authors or groups; 33 breaks by the site's rules.
A public finding is cited as its authors published it: the title is theirs and the link leads to their page. Its verdict is PQC-X's, computed by the same rules as for its own findings from what the report states; PQC-X has not reproduced it. 15 public reports that PQC-X reproduced or found independently are listed once, under PQC-X. Other teams' pages last checked on 2026-09-24.
Practical (6)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Practical | Facto-DSA | Key recovery | PQC-X · first public: Kris Kwiatkowski |
| Practical | Facto-DSA | The public key yields a universal signing trapdoor | MingLLuo |
| Practical | MAMBA-NIKE | Reused static key recovered | PQC-X |
| Practical | Origami | Universal forgery from the public key | PQC-X |
| Practical | Polar-KEM | No trapdoor in specification | PQC-X · first public: M.-J. Saarinen |
| Practical | Tins | One signature reveals the complete signing witness | Tianyuan Xie |
Theoretical (2)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Theoretical | CS | Verifier challenge-sign blindness enables universal forgery | Kris Kwiatkowski |
| Theoretical | HEP-QC | Public column multiplicities break the EPC-P assumption | Tianyuan Xie |
Minor break (25)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Minor break | Aigis-Sig+ | Message digest too short | PQC-X |
| Minor break | BiT | Message digest too short | PQC-X · first public: M.-J. Saarinen |
| Minor break | CEDRUS+C | Forgery against a verifier that follows the specification | PQC-X, after Mikhail Kudinov |
| Minor break | COMPASS-KEM | Seed, message and key too short | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: message recovery, quantum shortfall |
| Minor break | COMPASS-SIG | Message digest too short | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall |
| Minor break | CTL | Key-generation seed too short | PQC-X · first public: M.-J. Saarinen |
| Minor break | DARTS | Message digest too short | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall |
| Minor break | Facto-DSA | Message digest too short | PQC-X |
| Minor break | FlexTree | Forgery against a verifier that follows the specification | Mikhail Kudinov · reproduced by PQC-X |
| Minor break | HEP-QC | HEP-QC-7 has at most 256 bits of key-generation support | Markku-Juhani O. Saarinen |
| Minor break | Lore | Key seed too short | PQC-X |
| Minor break | Lore | Shared key too short | PQC-X |
| Minor break | MAMBA-NIKE | Secret seed too short | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: specified seed, passive claim too |
| Minor break | MAMBA-Viper | FO coin too short | PQC-X |
| Minor break | MORNING-ATLAS | Undersized challenge space | PQC-X |
| Minor break | MORNING-ATLAS | Message digest too short | PQC-X |
| Minor break | MORNING-ATLAS | Undersized master seed | PQC-X |
| Minor break | NIIKE | The raw shared j-invariant is distinguishable from a uniform key | Markku-Juhani O. Saarinen |
| Minor break | OAEP-NTRU | Malleable ciphertext byte encoding | PQC-X |
| Minor break | Origami | Message digest too short | PQC-X · first public: M.-J. Saarinen |
| Minor break | Origami | Signatures expose the hidden-algebra constraint subspace | Peigen Li |
| Minor break | Rhyme | Key recovery below level | PQC-X · first public: M.-J. Saarinen |
| Minor break | Rhyme | Digest collision forgery | PQC-X · first public: M.-J. Saarinen |
| Minor break | Tins | Quantum security below the call's floor | PQC-X |
| Minor break | TSUOV | Message digest too short | PQC-X* · first public: M.-J. Saarinen*PQC-X adds: the quantum shortfall |
Security proof gap (10)
| Verdict | Candidate | Finding | By |
|---|---|---|---|
| Security proof gap | Amoeba | Decryption failure rate understated | PQC-X · first public: Yijian Liu |
| Security proof gap | CheetahKEM | Decryption failures far above claim | PQC-X |
| Security proof gap | COMPASS-KEM | Decryption-failure rate understated | PQC-X |
| Security proof gap | DOVE | Proof analyses a different algorithm | PQC-X · first public: Dariia Porechna |
| Security proof gap | LoongKEM | Decryption failures far above claim | PQC-X |
| Security proof gap | MORNING-Scabbard | Decryption failures far above claim | PQC-X |
| Security proof gap | NEV | C2 failure rate underestimated | PQC-X |
| Security proof gap | Octarine | The stated hash requirement is too weak for the EUF-CMA target | Markku-Juhani O. Saarinen |
| Security proof gap | Octarine | Polynomial solutions of the relaxed Octarine-512 SIS estimates | Mounir IDRASSI |
| Security proof gap | VDOO | The VDOO-256 and -512 proof bound contains a 128-bit salt term | Markku-Juhani O. Saarinen |
Observations (32)
No claimed or required property falls, or the report establishes nothing yet; a limit of the placeholder hash is marked "not counted".
Where other teams publish
| Source | By | What it covers |
|---|---|---|
| ngcc.dev reports | M.-J. Saarinen | A tracker of reported vulnerabilities in all 119 candidates, collected from several teams, with reproduction steps |
| CryptHash public comment forum | ICCS | Public comments on the hash candidates: analyses by ISCAS and the Tsinghua Hash Lab, and the design teams' replies and errata |
| NGCC PKC public comment forum | ICCS | Public comments on the public-key candidates, with the design teams' replies and fixes |
| ngcc-harness issues | GitHub | Reports and reproduction code submitted to the ngcc.dev tracker |
| ePrint 2026/2152 | Y. Yuan, R. Wu, S. Wei, J. Shen, J. Liu, Y. Zhang (ISCAS, UCAS) | Structural weaknesses in seven of the hash candidates, among them MoFang, Neulaser, CHIME and CHAMP |
| ePrint 2026/1403 | S. Abelard, L. Perret, H. Shi | A polynomial-time key recovery on an earlier version of Facto-DSA |
| champ-cryptanalysis | M. Idrassi | A collision search on CHAMP, with certificates on reduced parameters |
| facto_dsa_ngcc_round1 | MingLLuo | A forgery on Facto-DSA-128 from the public key alone |