Quantum Unfiltered #15 — Three Attacks, Three Angles, One Answer
Implementation bugs, AI-assisted cryptanalysis, and a quantum algorithm aimed at lattice foundations. One summer. Three angles. One architectural lesson.
In this edition: Daniel Simon, the researcher whose 1994 algorithm helped inspire Shor’s, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem. A CRYPTO 2026 paper narrows the gap between the dihedral problem family and ML-KEM’s specific hardness assumption. I trace the reduction chain, identify where the proof is most vulnerable, and explain what it means for migration planning. This is the third event this summer hitting PQC from a different angle: Bernstein demonstrated ML-DSA key recovery in under one second by exploiting implementation flaws, Anthropic’s AI produced an original cryptanalytic result against the now-withdrawn NIST candidate HAWK, and now Simon’s claim targets the mathematical foundations. The lesson is cryptographic resilience. Also in this edition: Allianz published a quantum risk report that gets the capital thesis right and compresses the cryptanalysis too far. TrustAsia applied to Chrome’s experimental Merkle Tree Certificate test programme. Regulators and cyber authorities from Hong Kong to Switzerland keep setting gates. And vendors selling proprietary post-quantum algorithms get the Flapdoodle they deserve.
Simon’s Paper and the Summer That Made Crypto-Agility Non-Optional
I cancelled three meetings to read Daniel Simon’s paper. That happens maybe twice a year.
Simon, the creator of the algorithm that helped inspire Shor’s, claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (ePrint 2026/1591). Reductions published over the past two decades connect DCP and EDCP to LWE-family problems. Module-LWE is central to ML-KEM and is one of the assumptions used in ML-DSA‘s security analysis. The paper is preliminary, several proofs are sketches, and its final corollary on SVP and LWE rests on personal communications rather than published derivations. No concrete attack on any NIST parameter set is presented or costed. I am waiting for assessments from Micciancio, Peikert, Regev, Ducas.
Interesting related paper: Wen and Zheng at Telecom Paris (ePrint 2026/155, accepted to CRYPTO 2026) prove, under asymptotic parameter conditions, a quantum-polynomial equivalence between search Module-LWE and a structured dihedral variant, over the power-of-two cyclotomic rings with constant module rank. They reduce that structured variant to plain EDCP. This is relevant to ML-KEM because its ring and module-rank structure sits in the same setting. It is not a concrete reduction to standardized ML-KEM parameters: the theorem uses search formulations and Gaussian-error conditions, while ML-KEM uses fixed parameters and centered-binomial noise. But the reduction chain between Simon’s claim and the algorithms in your TLS stack has fewer structural gaps than most coverage acknowledges.
My working assessment: an unverified preliminary result with a potentially systemic consequence, no operational exploit, and immediate architectural relevance. I would not pause a single ML-KEM rollout over this.
I would, however, look very hard at how much of your migration rests on one branch of mathematics.
Three Attack Classes in One Summer
This is the third event this summer hitting PQC from a different angle. The pattern matters more than any single paper.
In June, Daniel Bernstein demonstrated that realistic ML-DSA implementation bugs can enable recovery of a signing-equivalent secret and universal forgery in under one second on one laptop core. The standardized algorithm itself was not broken; the demonstrations targeted buggy implementations that interoperate with correct ML-DSA and pass conventional tests. In Bernstein’s quantitative model, he assumes roughly 25% of newly written ML-DSA libraries initially contain a severe vulnerability. Under those assumptions, solo ML-DSA deployment produces about an order of magnitude more breakable keys than hybrid deployment for at least the first five years.
In July, Anthropic researchers reported an AI-assisted cryptanalytic result against HAWK. Claude Mythos Preview performed much of the mathematical search semi-autonomously, with occasional human guidance, and the team demonstrated key recovery against the small HAWK-256 parameter in roughly 60 hours. HAWK’s submitters withdrew it from the NIST process within 24 hours of the disclosure. The media coverage was predictably irresponsible (”AI can hack all encryption”), but the real lesson is specific: AI-assisted workflows can now contribute original mathematics to publishable cryptanalytic results faster and more cheaply than the traditional process. The attack exploits structure specific to HAWK’s design and does not transfer to ML-KEM, ML-DSA, AES, or any deployed algorithm.
And now Simon’s claim against the mathematical foundations themselves, with a peer-reviewed bridge connecting it to ML-KEM’s specific hardness assumption.
Three different failure modes: implementation bugs found by a human, an algorithm-specific AI-assisted cryptanalytic result, and a theoretical quantum algorithm targeting foundational lattice assumptions. The common architectural requirement is replaceability. Crypto-agility does not prevent these failures; it determines whether your organization can contain them by replacing algorithms without rebuilding every dependent system.
PQC is a set of technologies. Crypto-agility is the capability to change, and I use the term in its broad sense: detect a cryptographic weakness, decide on a response, deploy it by whatever means the situation permits. Replacement is one move on that menu. Hybrid composition is another, and Bernstein's order-of-magnitude gap between solo and hybrid ML-DSA is a result about that second move. Supply chain sits inside the definition too, because your ceiling is the slowest vendor you depend on. I have argued for agility as architecture for years, and Marin's Law still holds: migration time runs inversely to the agility already in place, so every unit built early is bought back several times later. This summer is the invoice for the units nobody built.
The specific HAWK and Simon/Wen mathematical results do not affect SLH-DSA, LMS/XMSS, or HQC. Bernstein’s implementation-risk lesson, however, is algorithm-agnostic: any newly implemented cryptography can fail in software.
Allianz Gets the Capital Thesis Right and Compresses the Cryptanalysis Too Far
Allianz Research published a quantum risk report for finance that is worth reading for one number and one observation, both of which are better than what most financial institutions produce.
The number: of every venture dollar committed to quantum, roughly 97% has gone to the technology stack and under 1% to financial-services applications. Capital markets are financing quantum capability much faster than institutional resilience.
The observation: PQC migration competes for the same engineers, cloud spend, and board time as AI initiatives, and AI offers more visible returns. That budget competition explains more about migration stalling than any technical analysis.
Where Allianz goes wrong: the report’s cryptanalytic chart compresses RSA and ECC resource estimates into a single qubit bar, hiding the multi-dimensional trade-offs between width, gate count, depth, and error-correction overhead. It recognizes signature-forgery consequences but does not structure Trust Now, Forge Later as a distinct risk class from HNDL. For Allianz’s own sector, that omission is the costliest: insurers pricing quantum risk in cyber policies need separate integrity and confidentiality scenarios.
TrustAsia Applies to Chrome’s Post-Quantum Certificate Test Programme
TrustAsia filed what appears to be the first CA application for Chrome’s experimental Merkle Tree Certificate test programme. The application has not yet been accepted. MTCs offer an alternative architecture for public Web PKI authentication: rather than attaching a full post-quantum signature to every individual certificate, the CA commits certificates into a Merkle tree and each certificate carries a compact inclusion proof. The size pressure is real. A DER-encoded ECDSA P-256 signature is around 72 bytes. An ML-DSA-65 signature is 3,309 bytes. SLH-DSA-128f is 17,088 bytes. MTC is designed to prevent those sizes from being multiplied across every certificate in every Web PKI chain.
This is infrastructure work rather than a user-facing product. But it is the kind of infrastructure work that will determine whether public Web PKI can adopt post-quantum authentication without imposing unacceptable bandwidth and latency costs across billions of clients.
Regulators and Cyber Authorities Keep Setting Gates
Hong Kong’s HKMA scored its banking sector 2.3 out of 10 on quantum readiness and set a sectoral objective of full readiness by 2030. FINMA recommends that Swiss supervised institutions establish board-backed PQC roadmaps by mid-2027. MAS announced that it will issue quantum-resilience supervisory expectations, including phased milestones and timelines, later in 2026. ANSSI intends to introduce PQC requirements into its product-qualification process from 2027. The UK NCSC and Vodafone published practical migration guidance based on an industry workshop.
The direction is converging across Asia, Europe, and the Anglosphere. The instruments differ (a readiness score, a roadmap recommendation, forthcoming supervisory guidance, a product-qualification gate, a workshop report), but for institutions in these jurisdictions, operating without a cryptographic inventory, an accountable owner, and a funded roadmap is becoming harder to defend.
Quantum Flapdoodle: Proprietary Post-Quantum Algorithms
If this summer taught us anything, it is that even NIST-reviewed algorithms, vetted by the world’s best cryptanalysts over eight years of public evaluation, face serious implementation vulnerabilities (Bernstein), AI-assisted cryptanalysis (HAWK), and credible theoretical challenges (Simon). NIST’s process is the most rigorous public cryptographic evaluation ever conducted, and the algorithms that survived it are still under active scrutiny.
Against that backdrop, I continue to encounter vendors selling proprietary post-quantum encryption schemes. Algorithms designed in-house, reviewed by nobody outside the company, published nowhere a cryptanalyst could examine them, and sold to enterprises as “quantum-safe” or “quantum-proof.” Several invoke Shannon’s name to imply information-theoretic security they do not deliver. Others claim “algorithmic agility” while locking customers into a single vendor’s unreviewed math with no interoperability and no migration path.
The test is simple. Four questions, and a “no” at any of them should stop the conversation: whether the algorithm is published, whether it has been through independent cryptanalysis, whether it is standardized or on a standards track, and whether you can replace it without rebuilding your infrastructure. A “no” at any of those four means you are betting your encrypted data on a scheme that has faced less scrutiny than the ones the cryptographic community is actively questioning this week. The whole point of crypto-agility is that you do not make irreversible bets on unproven math. Proprietary PQC is the opposite of that principle.
From the Applied Quantum Desk
PQC Migration Framework v2.1 released in June. The Applied Quantum PQC Migration Framework reached v2.1, completing the major revision cycle. Key changes: a two-track migration model separating key exchange (Track A, driven by HNDL exposure) from signatures (Track B, driven by TNFL risk); deployment environment classification (Unrestricted, FIPS-Aware, FIPS-Required, CNSA 2.0); SOC and GRC implementation sections; and all six sector extensions aligned on the v2.1 baseline. The framework is freely available and published under CC BY 4.0. For the complete change record: PQCFramework.com.
Applied Quantum is accepting participants for the next Quantum Academy live course cohort. Sessions cover PQC standards and migration, quantum computing fundamentals, the quantum threat to cryptography, and how to read vendor roadmaps. Contact us for scheduling and group rates.
If this edition was useful, forward it to a colleague who should be paying attention. If I got something wrong, hit reply. I read everything and correct publicly.
— Marin


