freenode
AnalysisSecurity & Cryptography

PQC timelines under pressure after HAWK collapse and McEliece parameter shocks

An AI-assisted lattice break and quasipolynomial claims against Classic McEliece reopening the fight over whether standardized post-quantum choices outran the cryptanalysis.

The post-quantum migration was already framed as a race against harvest-now adversaries when two cryptanalytic shocks hit candidates still close to the standardization track. An AI-assisted lattice attack cut HAWK's key-recovery dimension in half and forced its withdrawal from NIST's signature process. Almost simultaneously, new quasipolynomial claims against Classic McEliece left experienced voices on the pqc-forum questioning whether any of the scheme's proposed parameter sets still deliver their stated security levels. The paired results have revived a sharper dispute: whether standardized PQC choices and deployment clocks are running ahead of the analysis meant to underwrite them, leaving operators torn between migration urgency and parameter distrust.

Steve Weis announced an improved key-recovery attack against HAWK-n that "reduces to SVP in dimension n/2 + 1." In the gate-count model of AGPS'20 the cost for HAWK-512 fell from 2^150 to 2^108 and for HAWK-1024 from 2^288 to 2^182. A practical implementation recovered a HAWK-256 secret key end-to-end in a few hours on a single server. Weis was explicit about scope: "This result does not impact Falcon, ML-DSA, or other latticed-based schemes." The work was found by Claude "with minimal technical guidance from people." Daniel Apon checked it independently and replied, "Nice. It checks out independently for me." The HAWK team helped verify the result; withdrawal from the NIST process followed. The episode demonstrated that lattice signature designs still outside the finalized set can lose their security margin quickly, and that AI assistance can shorten the path from design claim to concrete break.

The McEliece discussion is different in technique yet similar in effect on confidence. Demi Marie Obenour highlighted eprint work by Ghoshal, Ishai, Jain, and Sun claiming a provable quasipolynomial-time distinguisher of Classic McEliece public keys from random bytes and a heuristic quasipolynomial decryption algorithm. "The claimed complexity of the distinguisher is below security level 1 for all parameter sets proposed by the Classic McEliece team," she wrote. "The attack is currently impractical, but if it works, it seems quite devastating for Classic McEliece and for Goppa McEliece in general." Restoring margins by enlarging parameters would drive ciphertext sizes toward quadratic growth in the security parameter. At that point, she asked, would the scheme retain any clear advantage over HQC or BIKE?

Subsequent papers and forum traffic pressed the higher categories. Christopher Peikert noted claims on the order of 2^102 bit operations against Category 3 and 5 sets previously advertised near 2^207 and 2^272, and asked whether it was "fair to claim that Classic McEliece is broken" for those parameters. Obenour's risk assessment was direct: "Structural attacks on Classic McEliece are rapidly improving. Is there a strong reason to believe that the current attack is the best possible? I don't see one." She added, "I would not be at all surprised if the parameters had to be adjusted yet again, or even if the scheme could not be saved at all." D. J. Bernstein challenged naive bit-operation tallies, arguing that the practical bottleneck is generating and routing on the order of 2^93 bits across large RAM fabrics, and that hardware price-performance for long-distance routing is far worse than a pure gate model suggests when set beside optimized AES-128 attack hardware. The exchange did not restore the original claims. It shifted the argument into cost models, memory hierarchies, and whether inflated parameters remain competitive once public keys move into the multi-megabyte range. Steve Weis posted corrected tables and parameter examples showing how far one must stretch (n, t) pairs before the new attacks sit behind 2^192 or 2^256, with corresponding public-key blow-ups.

These breaks arrive inside a community already divided on pace. Obenour argued that standardization need not be a gate: "One doesn't have to wait for a scheme to be standardized before deploying it." OpenSSH shipped Streamlined NTRU Prime before ML-KEM was finished in FIPS 203. For bandwidth-constrained settings such as certain Ericsson links, where only isogeny-based options fit, she suggested operators who control both ends can field research constructions such as MIKE, hybridized with ECDH and Kerberos-style symmetric keying, so that security holds if any component holds. Bas Westerbaan answered with adoption graphs illustrating how uneven post-quantum uptake already is across human-driven and automated clients. John Mattsson, focusing on the standards track, cautioned against presenting FrodoKEM as the default conservative choice given thinner deployment and scrutiny than ML-KEM, and recommended an ML-KEM plus HQC hybrid for diversification across hardness assumptions and better performance than Frodo alone. A broken DCP algorithm, he noted, would not have toppled HQC or non-commutative isogeny schemes such as SQISign and MIKE.

The through-line is calibration, not a single broken primitive. HAWK is out of the NIST signature process after an AI-assisted dimensional reduction that left Falcon and ML-DSA untouched. Classic McEliece's proposed parameter sets face active recommendations against them on the forum, with no settled answer on whether still-larger parameters preserve a usable niche or simply hand the size contest to HQC and BIKE. Finalized lattice KEMs and signatures are not directly implicated by either result, yet the surrounding confidence interval on how finished "finished" really is has widened. Deployers still face regulatory and harvest-now clocks that favor early hybrids, while successive structural improvements against both a late-round signature candidate and the longest-studied code-based KEM feed reluctance to trust advertised margins. Which hold-outs, which hybrids, and which parameter freezes are rational in the interim remains an open operational judgment rather than a settled cryptographic one.