freenode
AnalysisSecurity & Cryptography

HAWK break and McEliece caution feed doubts on PQC readiness

A practical key-recovery result on HAWK and a BSI warning against new Classic McEliece deployments crystallize skepticism about several post-quantum candidates just as migration clocks tighten.

Confidence in the next wave of post-quantum cryptography is fraying at the same moment institutions are being told to hurry. A practical key-recovery attack on HAWK, announced on the pqc-forum by Steve Weis of Anthropic, landed days before Germany's BSI told developers that Classic McEliece "should currently no longer be used in new developments or when planning new cryptographic applications." Together the episodes have sharpened an argument that has been building across the forum: several candidates still treated as serious options look less mature, and less deployable, than migration timelines assume.

Weis reported an improved key-recovery attack against HAWK-n that "reduces to SVP in dimension n/2 + 1." In the gate-count model of AGPS'20, the cost for HAWK-512 falls from 2^150 to 2^108 and for HAWK-1024 from 2^288 to 2^182. The team demonstrated the result end-to-end by recovering a HAWK-256 secret key "in a few hours on a single server." Daniel Apon independently checked the claim and replied simply, "Nice. It checks out independently for me." Weis was careful to bound the blast radius: "This result does not impact Falcon, ML-DSA, or other latticed-based schemes." The HAWK team helped verify the finding. The disclosure also noted that the weakness "was found by Claude, with minimal technical guidance from people," a detail that itself became part of the community's unease about how quickly lattice assumptions can be re-examined once search is automated.

HAWK had been valued precisely because it sat near Falcon in the design space while aiming for smaller signatures and simpler verification. Reducing key recovery to a much smaller SVP instance undercuts that positioning. Developers who had been watching HAWK as a possible alternative or complement now face the familiar post-quantum pattern: attractive parameters, then a sudden drop in concrete security once the attack surface is probed harder. The practical HAWK-256 break makes the drop hard to dismiss as asymptotic.

Almost in parallel, Tobias Hemmert relayed BSI's formal note on Classic McEliece. The agency did not claim a total break of the scheme in every parameter set, but it drew a bright operational line against new use. BSI also reiterated that hybrid constructions had "proven its worth," because a hybrid with Classic McEliece "still provides at least the security of the classical scheme." That formulation immediately split the room.

John Preuß Mattsson welcomed the clarity and drew a broader lesson: only algorithms that have "been standardized through open, transparent processes and have already seen large-scale international deployment" deserve primary reliance. Classic McEliece, in his view, fails both tests. He pushed further on hybrid design. "At least the security of the classical scheme" is cold comfort for anyone who adopted PQ/T hybrids specifically for quantum resistance. After recent scares, including alleged polynomial-time algorithms for related problems, he wrote that he has "become even more convinced that PQ/PQ hybrids make a lot of sense for key exchange in high-security systems," citing combinations such as ML-KEM with HQC-KEM so that quantum resistance survives if either component holds.

Oscar Smith rejected the implication that classical fallback is worthless for quantum goals. "A PQ/T hybrid absolutely helps people who want quantum resistance," he argued, because a 2048-bit RSA component remains out of reach for any quantum computer that lacks thousands of logical qubits. If the post-quantum half fails, the hybrid still resists every machine that exists today. Bas Westerbaan called that a "creative argument" that does not match how "quantum resistant" is commonly understood. Uri Blumenthal sharpened the same point: by that logic, "pure ECDH over P-384 provides quantum resistance to 100% of currently built quantum machines." The exchange left the practical question unresolved. Operators must decide whether hybrid policy is a bridge to cryptographically relevant quantum computers or merely a way to keep classical security while PQ algorithms keep failing.

A second thread running through the same weeks concerns agency: who is allowed to ship what before standards and national guidance settle. Demi Marie Obenour argued that waiting is optional when one controls both ends of a protocol. "One doesn't have to wait for a scheme to be standardized before deploying it," she wrote, pointing to OpenSSH's earlier use of Streamlined NTRU Prime. "As long as it is not broken, any post-quantum asymmetric cryptography is strictly better than no post-quantum asymmetric cryptography." She extended the point to constrained settings such as Ericsson's, where isogeny-based designs may be the only fit for size, provided client and server ship together and hybrids with classical and symmetric layers remain available as belts and suspenders.

Bas Westerbaan answered with adoption data suggesting machines are already ahead of humans in turning PQ on. A small production data point from John Edward Romo Sánchez at FractalAI fit the pattern: autonomous agents consuming ML-DSA-65 signed responses over a payment protocol exercised key directories without complaint, while human buyers still asked first whether the stack was "FIPS validated." The contrast is double-edged. It shows that controlled environments can move fast, yet it also shows that the algorithms humans will actually bless still orbit the standardized lattice suite. Unstandardized or recently bruised candidates remain easier to enable in bots than in regulated products.

What ties the HAWK result to the McEliece warning is not a single mathematical family but a timing problem. Migration programs, procurement language, and protocol drafts are locking in choices now. Each new concrete attack or agency retreat raises the cost of having bet on a finalist that was still lightly analyzed in its proposed parameters. Falcon and ML-DSA are repeatedly carved out as unaffected, which concentrates traffic onto fewer designs and makes diversity claims harder to sustain. Code-based and other non-lattice options look less like ready spares when national bodies advise against new Classic McEliece use and when hybrid theology itself is contested.

The unresolved issues are therefore operational rather than purely academic. How much concrete-security margin must a signature or KEM demonstrate before it is safe to treat as a migration target. Whether PQ/T hybrids are a temporary classical safety net or a standing requirement until two independent PQ primitives are both boring. Whether controlled bilateral deployments of nonstandard schemes are a responsible hedge or a way to accumulate future breakage. And how guidance bodies should react when an attack is both theoretically cleaner and practically demonstrated, as with HAWK-256, without waiting for every parameter set to fall.

For now the standardized lattice core remains the default path, HAWK's standing as a near-term option is badly damaged, and Classic McEliece has been pushed out of greenfield designs by at least one major national authority. The community has clearer negatives than positives: more schemes to de-prioritize, sharper disagreement on hybrid goals, and less time before deployment decisions become expensive to reverse.