Charles Hoskinson challenges Vitalik Buterin’s case against lattice cryptography

Charles Hoskinson challenges Vitalik Buterin’s case against lattice cryptography

N
News Editor
2026-10-09 03:25:29
Cardano founder Charles Hoskinson pushed back on Vitalik Buterin’s criticism of lattice-based cryptography, arguing that the case against it relies on analogy rather than formal proof. In a post on X, Hoskinson said the objections are based on comparisons to the General Number Field Sieve, intuition about “structure,” and claims about key-size expansion that lack a supporting formula and have not been validated over the past several decades. He also said Buterin’s notation for GNFS complexity was incorrect. According to Hoskinson, LLL, BKZ, and sieving have already been incorporated into the security parameter analysis for ML-KEM and ML-DSA, while quantum attacks on ideal lattices have not reached those two module-lattice schemes. He added that hash functions also contain mathematical structure that can be studied and attacked, citing Poseidon as an example because it uses low-degree polynomial mappings. Hoskinson said a 10x key expansion has no complexity formula behind it, arguing that constant-factor improvements imply proportional dimension adjustments rather than a fixed multiplier of 10. He warned that excessive doubt around deployed hybrid ML-KEM schemes could slow post-quantum migration as “harvest now, decrypt later” risks draw more attention. He also said hash-based signature schemes have practical value, but are difficult to use as a replacement for common elliptic-curve cryptography functions.

Cardano founder Charles Hoskinson said on X that Vitalik Buterin, because of his deep involvement in hash-based cryptography research, is trying to persuade the industry that lattice cryptography is unreliable.

Hoskinson argued that the case against lattice cryptography rests mainly on analogy to the General Number Field Sieve, intuition about “structure,” and key-expansion claims without formula support, adding that those arguments have not been validated over the past several decades.

He also said Buterin’s post contained an error in how GNFS complexity was written. Hoskinson added that LLL, BKZ, and sieving have long been included in security parameter assessments for ML-KEM and ML-DSA, and that quantum attacks on ideal lattices have not reached those two module-lattice schemes.

He said hash functions also have mathematical structure that can be studied and attacked. As one example, he pointed to Poseidon, which uses low-degree polynomial mappings. On the claim that keys should be expanded by 10x, Hoskinson said there is no complexity formula supporting that view. In his description, constant-factor improvements correspond to proportional changes in dimension, not a fixed multiplication by 10.

Hoskinson also warned that, as concern grows around “harvest now, decrypt later” threats, excessive skepticism toward already deployed hybrid ML-KEM schemes could slow the migration to post-quantum cryptography and leave more communications data exposed to the risk of future decryption by quantum computers.

At the same time, he said hash-based signature schemes do have practical value, but are difficult to use as a substitute for the common functions provided by elliptic-curve cryptography.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.