Key Highlights
- Hoskinson argued that the mathematical techniques behind the general number field sieve do not translate directly to lattice-based cryptanalysis.
- He cited advances in lattice attacks, including LLL, BKZ, and sieving methods, while noting that ML-KEM and ML-DSA parameters account for known attacks.
- Buterin warned that AI-driven advances in mathematics could threaten lattice-based schemes and advocated hash-based signatures where feasible.
Cardano founder Charles Hoskinson has responded to remarks by Ethereum co-founder Vitalik Buterin on the relative security of lattice-based and hash-based cryptography in the context of potential advances from artificial intelligence.
In an X post on Friday, Hoskinson argued that the comparison to the general number field sieve does not apply directly to lattices. He stated that the number field sieve relied on specific arithmetic properties involving smooth numbers, factor bases, and linear algebra, and that no equivalent structure has been identified for lattices that would produce a similar breakthrough. He noted that the sieve was completed by 1993 and that RSA key sizes have changed little in the decades since.
Hoskinson said lattice cryptanalysis has already incorporated successive improvements, including the LLL algorithm, introduced in 1982, followed by later improvements to BKZ, enumeration and sieving methods that reduced the exponent from 2^0.415n in 2008 to 2^0.292n in 2016. He stated that ML-KEM and ML-DSA parameters were selected against these known attacks under conservative cost models.
He further noted that results by Gentry, Gentry, Peikert, and Vaikuntanathan, along with Peikert, establish that solving random learning-with-errors or short integer solution instances at appropriate parameters is equivalent to solving approximate shortest-vector problems on lattices of the corresponding dimension. Hoskinson contrasted this with the security of hash functions such as SHA-256, which rests on the absence of known breaks rather than a comparable reduction.
Buterin’s comment on AI and crypto risks
Buterin had stated that AI-accelerated mathematics could pose risks to lattice-based schemes such as ML-DSA and fully homomorphic encryption. He noted that Ethereum’s lean roadmap has moved toward hash-only constructions for signatures, using schemes such as WOTS or SPHINCS-.
For public-key encryption, which mathematical results indicate cannot rely solely on hashes, Buterin suggested that larger parameter sizes may be required if AI produces improvements comparable to the shift from naive factoring to the general number field sieve. He also advised greater caution with lattice-based systems outside blockchains, including in secure messaging and anonymizing protocols.
Discussion of structure and specific schemes
Hoskinson addressed concerns about algebraic structure in lattices by referencing quantum attacks on ideal shortest-vector problems in cyclotomic fields published by Cramer, Ducas, Peikert, and Regev in 2016 and by Cramer, Ducas, and Wesolowski in 2017, as well as research on attacks against NTRU-related constructions.
He stated that these results affected certain schemes but do not apply to module-lattice constructions such as ML-KEM and ML-DSA, which use small moduli. He added that subsequent analysis showed the quantum ideal attacks perform worse than plain BKZ at relevant dimensions and that standards bodies retained FrodoKEM, which avoids rings, and added HQC in 2025 to diversify key-encapsulation mechanisms.
On hash functions, Hoskinson observed that differential cryptanalysis had broken MD5 and SHA-1 by exploiting properties of their round functions. He noted that Poseidon and Poseidon2, used in some hash-only designs, are low-degree polynomial maps over small prime fields and have been the subject of Gröbner-basis and interpolation research, including a cryptanalysis bounty funded by the Ethereum Foundation.
Proof systems and theoretical claims
Hoskinson stated that proof systems such as FRI, STIR, and WHIR at aggressive parameters rely on unproven Reed-Solomon proximity-gap conjectures and the random-oracle model for Fiat-Shamir.
He also addressed theoretical points, noting that the Impagliazzo-Rudich result is a black-box separation concerning proof techniques rather than a demonstration that public-key encryption requires structure and that Merkle puzzles provide hash-only key agreement with a quadratic gap shown to be optimal in that model by Barak and Mahmoody.
He said parameter adjustments for lattice schemes follow from changes in the constant of the attack exponent 2^(c·β) and do not correspond to a uniform tenfold increase in key size. Hoskinson added that extraordinary claims in the field are typically examined through public scrutiny, citing the rapid identification of a bug in a 2024 preprint claiming a quantum polynomial-time algorithm for learning with errors, as well as the breaks of Rainbow and SIKE during the NIST process.
Context of the exchange
Buterin’s earlier comments recommended favoring hash-based constructions where feasible, applying more conservative parameters to lattice-based systems, avoiding on-chain encrypted notes in privacy protocols, and considering unused addresses for funds while exercising care with migrations.
Hoskinson’s reply focused on the technical arguments regarding attack history, reductions, standardized schemes, and the practical status of hybrid ML-KEM deployments.
The exchange centers on differing assessments of the maturity of lattice cryptanalysis relative to hash-based alternatives and the implications of potential future advances in mathematical techniques.
Also Read: Jito Details Validator Requirements Ahead of Solana Alpenglow Upgrade
