[CFRG] Fwd: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1

Dmitry Belyavsky <beldmit@gmail.com> Sun, 09 August 2026 20:10 UTC

Return-Path: <beldmit@gmail.com>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3AD65126BE070 for <cfrg@mail2.ietf.org>; Sun, 9 Aug 2026 13:10:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786306235; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; h=References:In-Reply-To:From:Date:Subject:To; b=v75eHoPWFmg5MUxzebyKAdCXp1Y9/o55pvKgZotNajsGg8Il1UeL60t9v565U3WJj z+p177gDtrUxsH3LvZzShL2Pd8PplUmV6kk2gjAyEZbJRSnk5UQOFvBotcCKhzOb9i la9/h8bzGOLIL5fulUyqL4bifcwfDnmSk3Rcn+So=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: 0.911
X-Spam-Level:
X-Spam-Status: No, score=0.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9kGnzFnwuVHf for <cfrg@mail2.ietf.org>; Sun, 9 Aug 2026 13:10:33 -0700 (PDT)
Received: from mail-qt1-x82d.google.com (mail-qt1-x82d.google.com [IPv6:2607:f8b0:4864:20::82d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 21066126BE06B for <cfrg@irtf.org>; Sun, 9 Aug 2026 13:10:33 -0700 (PDT)
Received: by mail-qt1-x82d.google.com with SMTP id d75a77b69052e-51c2cce930cso12413471cf.0 for <cfrg@irtf.org>; Sun, 09 Aug 2026 13:10:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786306233; cv=none; d=google.com; s=arc-20260327; b=LHjT+2Vzpa6kENk91mrpZMRAywGTEUvvOPdwMh+DYGLgYK4lsRhkF5lNXTjjz/ApMg 1Vq8fzjhecMgcpwW/JFiQm4FqEXnFScehKvCKkEtwGfH1iB4BfLgYJSe2zc0ZaAlU0Wd gFSMJyGGFREoFIMNSwZhctwQKZV6x1j5o9hcUTFfl/+CzjawtfhXy7qd22U6z/zYpW9o ba1b+S+snbC8pH598rLAFdWorOqoHb62UjGBgnNXLdpNQnw49NMyKdYWTs99iesNQHII HT6g12jyA3BM4LnKi7QTfd0QmPKHwF8GsWliTpNV4Xlh/LuKWjhiAUOEC5yK03O5Xn7B RDsw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; fh=0OpMRY94qnbm+W1rj3DPPWa2vbm2oOGhvNxXhXnx9G4=; b=EzlKhFlUmGWKWw5pECt9GitcyNwbVSdsM/pHoY+pbsGsoCu3Q+B8EHHa0+P5c2QVSD lXgnjV2s4jkn0y7oAxOkyo9pb+Gkh/VZ03UxGgkY655mzESuELr8LtBK37G64mI1pasL jW2ACFlf+StP8ISHuEYRZCRo5Q2KFJ86sCxDRxGfl2LPoeDIxPBb2EtI3s3SnMnBx8BS aROinoG9MRZi2WBSGdx4blqVVhgyL5ANNljayX1Kp7bmbEwIwtnBUGwju9VuPUQBdhJV D7Bo/CR3ahikTaJeGCFzLesxoC4CjjU2wsFp/wJF4pUaBEX1wo7hEvR24/3HigmO2LyK 4rUA==; darn=irtf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786306233; x=1786911033; darn=irtf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; b=T9VjAtiJHk2dZnrIxRgf16iNksuPwxv69pLy+JQeOoHVmpSjIhRs+004RMIIGzeTCA LI0I1cHiaviZkChCFWaHB+s5g43g5YgGOdMLz6WaRX1honL+lDJJgDh91lr5gzTn/pi+ i4s/YbRnJaEbFaC/QFSefnuHtOZ7Hlsrd4XCFLGxyv7LOBAhdL5cHHyBndsrgUO4KfwE r+UoWxBSsCsl9tZCGGRd8bVPFtDwAHLyRY6zMbTfSdggjpR3Vd8mrUDIFiExLpxoVdaV vSnUx47X8lKNrVKf2xQy+00JpRu49Aduw3ei9vE5CuqCHe7BkFd1qUrr1uqMxRURhpUq +sOg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786306233; x=1786911033; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IoQW9jDtxhQYmPY139QP7499ILGOzT45sjhqB/WHUzM=; b=f9hhg8QPllIk3OlN9ttkeiQYX6NJ3J52ygJPHDPG8rXZGDHvG2r5VjM9oVgYI8re/Z mrbNbRC8UJva70WzR5aEkdbqIiHdHyUezz7f9cr0YmnlPu9G6yRPm4JE/iQzFkP4cNSH oIpWVktMnc7uUnRiKpRCWzv7/CJobTY20eI3KI7ToAKxa+eb9tTWOFLPS//Z/7EQW5e/ 3yWRVXULYgQ1nmDu8DgdAvLg9mdddyjI9U1tlP6obISYnCS5Ie46H0Y80z7Y51easZsr 67tHnLhQc5Iu1G+GAKNd2R+DtxWgzoheDUQxuw1nCy6OfT0HfZBO1boIn2sn6JILzNEK gU2A==
X-Forwarded-Encrypted: i=1; AHgh+Rq4m2A+aHzUoXj1phShFEH929RuiJ7hVi59rzX1pgX9myyxWbshY8Ou7DXNSCxHAv9e4t8o@irtf.org
X-Gm-Message-State: AOJu0YzTF90GT2J9j8Pfc+rDNVToDKRX6DuWxuhb9aXAWTVDHPpZxw3B zazCflZRrsQ75l+07OpFjJHpYaRHJBmEP6A/fFV5HtUlqaY320za+QKTC4LC3QcJa0zJmtO6934 sh+Kd/qBwpMic5RvvRlZ0zj4vIXC6Gyo=
X-Gm-Gg: AR+sD1064jGpArRCB8RWs3DIDKholcPfMHFJOSflbbcn8ITLLQUAg+n+j1k9tLWLzja KIGp6m/KMTVqow2Om90H44P8loNvYb11n3Da1mt+jNgtNncetcI3Q+zTaIO4c0VLEKsKOPf2pve gr09jqTS3G4VOzTp8ag1Gfpoo/iH/kND4j7b9F1PblsKc9qW9jsBWJfKjRQ7xKyjJZSKFN3hYZ7 zx7WDb9YfLO4GHoLYuMMTaXdKUoFIYkwBloFiOLPehUIAHoDFNh3SHYRiCH61UZTu5jEhZ87ydT Ii/4C/3GG4kG+VC8vS2x4oOh3Kff1ltLWT+jTEzLYjbSLNRvWBDvwD0wlkqkFmv8TXdy
X-Received: by 2002:ac8:6903:0:b0:527:7027:cc1b with SMTP id d75a77b69052e-52d0b220c2cmr283478711cf.32.1786306232428; Sun, 09 Aug 2026 13:10:32 -0700 (PDT)
MIME-Version: 1.0
References: <CAAUmCcC6ERGedfyN2kWeiBmeg+4Q+UgMpLXGrXvBLwwfEPkJkA@mail.gmail.com> <09f45a33-bf7c-42cd-956d-ad4fecaccf3cn@list.nist.gov> <CANWGDp8sEpC7bH0phZO8dMW5zyeFMh3kyR=hDASG=w06HQ6prw@mail.gmail.com> <5d998299-9203-4171-9f42-7ec93d118786n@list.nist.gov> <43aea96a-98bd-46cb-a7e1-0b11d094d40cn@list.nist.gov> <CA+iU_qkUtn3xNxy0V1y7kKhpmK+kKsPyyW1ZCFOLtKs04f1xkw@mail.gmail.com>
In-Reply-To: <CA+iU_qkUtn3xNxy0V1y7kKhpmK+kKsPyyW1ZCFOLtKs04f1xkw@mail.gmail.com>
From: Dmitry Belyavsky <beldmit@gmail.com>
Date: Sun, 09 Aug 2026 22:10:19 +0200
X-Gm-Features: AUfX_mzDYcvwjx7YznowcuYuGKAWQCW97rixiCZBo5YEji-Xo6fncnjjbB6aBDo
Message-ID: <CADqLbz+XWy-DGt2XrSuFx3j5d4YStbsYBY01EQBZ6pb42smn0Q@mail.gmail.com>
To: ssh <ssh@ietf.org>, cfrg <cfrg@irtf.org>
Content-Type: multipart/alternative; boundary="00000000000071ae1e0658a2d44c"
Message-ID-Hash: 6FNNISPLEBCNDXZYTEEAKHFJ3VL2AIRX
X-Message-ID-Hash: 6FNNISPLEBCNDXZYTEEAKHFJ3VL2AIRX
X-MailFrom: beldmit@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Fwd: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/up07pneeS0B07SzykD_lf5wV4PQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

As the discussion of this paper takes place at multiple ML and this email
looks like a relevant evaluation, I want to share it.

SY, Dmitry Belyavsky

---------- Forwarded message ---------
Od: Markku-Juhani O. Saarinen <mjos.crypto@gmail.com>
Date: ne 9. 8. 2026 20:57
Subject: Re: [pqc-forum] Re: HAWK-n Key Recovery Reduces to SVP in
Dimension n/2 + 1
To: Cong Ling <cling74@googlemail.com>
Cc: pqc-forum <pqc-forum@list.nist.gov>


On Sun, Aug 9, 2026 at 5:58 PM 'Cong Ling' via pqc-forum <
pqc-forum@list.nist.gov> wrote:

> A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem
> <https://eprint.iacr.org/2026/1591>
>
> Has anyone independently checked the proof in this paper, either manually
> or using a formal proof assistant such as Lean?
>

Dear Cong Ling & Co,

Well, the paper just came out a couple of days ago (and many of the lemmas
are sketches.) Initial, direct attempts to check the proofs fail -- Lemma
3's central independence claim doesn't work as stated (it spends randomness
in D twice), and Lemma 4 applies unconditional hashing bounds after heavy
quantum conditioning. So the main proofs don't hold exactly as stated.

But it is important to note that a bug in the proofs doesn't demonstrate
that the algorithm itself doesn't work (which is really the more important
point from a cryptanalytic viewpoint). One can also restate the main
Theorem, if necessary.

So the community would indeed be very curious to know whether anyone has
found a way to repair the paper -- or found substantial evidence against
the algorithm.

However, there is a consensus that even if the paper's proof of correctness
and reductions were repaired, this would not threaten the quantum security
claims of NIST PQC algorithms. Such a result would be asymptotically
important, but its concrete quantum resource costs are too high.

ps. I'm obviously not the only one who has used GPT-5.6 Sol and Fable 5 on
this, and ran extensive computational experiments.I have a fairly generous
45-minute slot at WAC 8 (Workshop on Attacks in Cryptography, a Crypto
2026-affiliated event at UCSB on Sunday, August 16). I'm turning the
original title (on Hawk Guessing Game) into a subtitle and will intead talk
mostly about AI Cryptanalysis, including my attempts to prove this DCP
paper. https://wac8.cryptanalysis.fun/

Best Regards,
-markku

Dr. Markku-Juhani O. Saarinen <mjos@iki.fi>



>
> On Monday, August 3, 2026 at 11:03:33 AM UTC+1 Alice Pellet-Mary wrote:
>
>> Dear Betül,
>>
>> To answer your questions, we have worked on this since the end of May, so
>> for approximatively 2 months (maybe a few weeks more for Guilhem). In terms
>> of budget, we did not use any costly tool, so that would be mostly human
>> (salary) cost. We weren't working full time on it at all, so I would say a
>> safe upper bound on the cost would be 2 person*month.
>>
>> Best regards,
>> Alice
>> Le samedi 1 août 2026 à 00:31:14 UTC+2, Betül Durak a écrit :
>>
>>> That’s pretty cool. Did they say how much budget they had/used and how
>>> long it took?
>>>
>>> On Fri, Jul 31, 2026 at 08:10 Damien Robert <damien.oli...@gmail.com>
>>> wrote:
>>>
>>>> Here is a message by Guilhem Mureau and Alice Pellet-Mary that they
>>>> asked me to post on their behalf.
>>>>
>>>> --------------------------------------------
>>>>
>>>> Dear all,
>>>>
>>>> We would also like to share a third key recovery attack on Hawk whose
>>>> result is very similar to the one of Hengyi Luo [2], even though we use
>>>> yet another mathematical tool. Our article should appear soon on
>>>> ePrint,
>>>> and is accessible for the moment here:
>>>>
>>>> https://apelletm.pages.math.cnrs.fr/page-perso/documents/articles/trace-zero-attack.pdf
>>>> <
>>>> https://apelletm.pages.math.cnrs.fr/page-perso/documents/articles/trace-zero-attack.pdf
>>>> >
>>>>
>>>> Our attack builds on our previous reduction from rank-2 module-LIP in a
>>>> cyclotomic field K to the norm reduced principal ideal problem (nrdPIP)
>>>> in a quaternion algebra [1]. We show that this nrdPIP instance can
>>>> itself be reduced to module-LIP in a module of rank 3 over the maximal
>>>> totally real subfield F of K. This allows us to reduce module-LIP in
>>>> modules of rank 2 in K to module-LIP in modules of rank 3 in F (note
>>>> that the degree of F is half the degree of K, so we are reducing the
>>>> lattice dimension by a factor 3/4).
>>>>
>>>> Applying this to Hawk, we obtain a key recovery attack on Hawk which
>>>> makes SVP calls in lattices of dimension at most 3n/4+1 (where n is the
>>>> degree of K), which is similar to the attack obtained by Hengyi Luo
>>>> [2].
>>>> The attack of Zygimantas Straznickas and Steve Weis [3] achieves an
>>>> even
>>>> smaller dimension for the SVP calls (namely n/2+1).
>>>>
>>>> The attack itself is quite simple. We wrote a detailed technical
>>>> overview section which we hope can be understood by any cryptographer
>>>> interested in module-LIP, so that they can get an idea of how the
>>>> attack
>>>> works without reading the full paper.
>>>>
>>>> In the upcoming weeks, we plan to investigate the relationship between
>>>> the three attacks. Given the strong similarities between the results,
>>>> it
>>>> seems that the three attacks may be doing very similar things with
>>>> different formalism.
>>>>
>>>> Implementation: we did a toy implementation of our attack in SageMath
>>>> (available here:
>>>> https://plmlab.math.cnrs.fr/apelletm/attack_hawk-trace-zero) We only
>>>> implemented the new part of the attack, i.e., the algorithm that solves
>>>> nrdPIP via module-LIP in modules of rank 3 over F. Due to limited
>>>> computational resources, we were able to run the attack only until n =
>>>> 128 (which runs in 2 hours on a laptop and uses BKZ with blocksize 30).
>>>> The point of the implementation was mostly to make sure that there was
>>>> no mistake in our proofs or that we did not overlook something, and the
>>>> results are satisfactory.
>>>>
>>>>
>>>> Guilhem Mureau and Alice Pellet-Mary
>>>>
>>>>
>>>> LLM disclaimer: We would like to acknowledge that this was found by
>>>> humans, with minimal technical guidance from LLMs. More precisely, we
>>>> used LLMs for improving the editorial quality of some parts of the
>>>> article, and for answering some technical mathematical questions that
>>>> we
>>>> had about quaternion algebras.
>>>>
>>>> References:
>>>> [1] Chevignard, C., Mureau, G., Espitau, T., Pellet-Mary, A., Pliatsok,
>>>> H., & Wallet, A. A reduction from hawk to the principal ideal problem
>>>> in
>>>> a quaternion algebra. Eurocrypt 2025. ePrint 2025/287
>>>> <https://eprint.iacr.org/2025/287.pdf>[2] Luo, H. Adjoint-Lattice
>>>> Reduction for the HAWK Gram-Factor Problem. link
>>>> <
>>>> https://harylo.github.io/files/preprints/adjoint-lattice-reduction-for-the-hawk-gram-factor-problem.pdf
>>>> >
>>>> [3] Straznickas, Z. and Weis, S. HAWK-n Key Recovery Reduces to SVP in
>>>> Dimension n/2 + 1. link
>>>> <
>>>> https://www-cdn.anthropic.com/e8d50c167ad47beeb03d6109a4a484be95cb38ea/hawk_key_recovery.pdf
>>>> >
>>>>
>>>>
>>>> On Tuesday, July 28, 2026 at 7:06:14 PM UTC+2 Steve Weis wrote:
>>>>
>>>>> Hello pqc-forum. We would like to announce an improved key recovery
>>>>> attack against HAWK-n that reduces to SVP in dimension n/2 + 1. The paper
>>>>> will appear at https://anthropic.com/document/hawk_key_recovery.pdf and
>>>>> is linked to from an accompanying blog post that will shortly be live:
>>>>> https://www.anthropic.com/research/discovering-cryptographic-weaknesses
>>>>>
>>>>> In the gate-count model of AGPS'20, the improved attack lowers the
>>>>> key-recovery cost of HAWK-512 from 2^150 to 2^108 and of HAWK-1024 from
>>>>> 2^288 to 2^182. We demonstrate this with a practical implementation that
>>>>> recovers a HAWK-256 secret key end-to-end in a few hours on a single
>>>>> server. The implementation can be found at:
>>>>> https://github.com/anthropics/cryptography-research-demo
>>>>>
>>>>> This result does not impact Falcon, ML-DSA, or other latticed-based
>>>>> schemes.
>>>>>
>>>>> We would like to thank the HAWK team for their help verifying this
>>>>> result and for their feedback. We would also like to acknowledge that this
>>>>> was found by Claude, with minimal technical guidance from people. For more
>>>>> information on the process, please refer to the above blog post.
>>>>>
>>>>> Thank you very much.
>>>>>
>>>> --
>>>>
>>> You received this message because you are subscribed to the Google
>>>> Groups "pqc-forum" group.
>>>> To unsubscribe from this group and stop receiving emails from it, send
>>>> an email to pqc-forum+...@list.nist.gov.
>>>>
>>> To view this discussion visit
>>>> https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/09f45a33-bf7c-42cd-956d-ad4fecaccf3cn%40list.nist.gov
>>>> <https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/09f45a33-bf7c-42cd-956d-ad4fecaccf3cn%40list.nist.gov?utm_medium=email&utm_source=footer>
>>>> .
>>>>
>>> --
> You received this message because you are subscribed to the Google Groups
> "pqc-forum" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to pqc-forum+unsubscribe@list.nist.gov.
> To view this discussion visit
> https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/43aea96a-98bd-46cb-a7e1-0b11d094d40cn%40list.nist.gov
> <https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/43aea96a-98bd-46cb-a7e1-0b11d094d40cn%40list.nist.gov?utm_medium=email&utm_source=footer>
> .
>
-- 
You received this message because you are subscribed to the Google Groups
"pqc-forum" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to pqc-forum+unsubscribe@list.nist.gov.
To view this discussion visit
https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/CA%2BiU_qkUtn3xNxy0V1y7kKhpmK%2BkKsPyyW1ZCFOLtKs04f1xkw%40mail.gmail.com
<https://groups.google.com/a/list.nist.gov/d/msgid/pqc-forum/CA%2BiU_qkUtn3xNxy0V1y7kKhpmK%2BkKsPyyW1ZCFOLtKs04f1xkw%40mail.gmail.com?utm_medium=email&utm_source=footer>
.