Quantum-safe algorithms may fail faster with powerful AI tools From SIKE

Understand this faster with AI
A cryptographic algorithm once considered a leading candidate for quantum-resistant encryption fell in just one hour on a standard laptop, not to a quantum computer, but to a mathematical insight from 1997.
The Supersonic Multivariates Isogeny Key Encapsulation (SIKE) protocol advanced to the fourth round of evaluation by the National Institute of Standards and Technology before mathematicians Wouter Castryck and Thomas Decru connected its structure to Ernst Kani’s decades-old theorem. This collapse highlights a growing vulnerability, as frontier AI systems now possess the capacity to rapidly explore obscure mathematical connections, potentially shortening the window between overlooked weakness and successful attack, according to security leaders. “Years without a successful attack provide evidence, but they cannot establish that every useful mathematical connection has been explored,” the researchers noted. In May 2026, OpenAI reported that an internal model disproved a longstanding conjecture associated with Erdős’s planar unit-distance problem, first posed in 1946. The model applied sophisticated algebraic number theory to a seemingly elementary geometry question, a transfer of ideas between fields that produced a major result. This month, OpenAI announced an AI-generated solution to the Navier-Stokes existence and smoothness problem, unresolved for roughly 90 years, and released both a written proof and a formalization for computer verification. The announcement remains subject to mathematical scrutiny, but the progression is stunning. Frontier systems are now producing research claims against problems that have occupied generations of the best mathematicians. It is certain these capabilities to accelerate the search for overlooked cryptographic weaknesses are being used on a vast scale, especially by intel agencies with enormous grid-straining compute, long before AI made it cool. Would models have independently broken SIKE in hours? Would it have happened in secret or made public? What has been demonstrated is AI’s growing ability to search professional literature, propose mathematical connections, write experimental code and investigate thousands of ideas to discover what works. AI Demonstrates Rapid Advancement in Solving Mathematical Problems This shift demands a re-evaluation of security strategies, moving beyond simply replacing vulnerable algorithms to minimizing the consequences when those replacements themselves are compromised.
Mathematicians Wouter Castryck and Thomas Decru identified a connection between SIKE’s structure and Kani’s 1997 theorem, enabling them to recover a private key for the protocol’s smallest parameter set in approximately one hour using a standard laptop. Larger parameter sets also proved vulnerable, requiring only conventional computing hardware. This rapid collapse emphasises a fundamental challenge in cryptographic security: years without a successful attack do not guarantee the absence of undiscovered vulnerabilities, particularly as AI expands the potential for mathematical exploration. The implications extend beyond SIKE, as demonstrated by recent advancements in artificial intelligence capable of tackling long-standing mathematical problems. External mathematicians verified the proof, noting the model’s application of sophisticated algebraic number theory to a seemingly elementary geometry problem. This capability is not merely academic. It is actively being applied to cryptographic analysis. Intelligence agencies, with their vast computational resources, have undoubtedly been using these tools long before the recent surge in public AI development. Anthropic reported in July 2026 that Claude Mythos Preview helped discover an improved attack against HAWK, a post-quantum digital-signature candidate, exploiting a previously unused symmetry in its lattice structure. The attack substantially reduced estimated security, although larger parameter sets remained impractical to attack, and the method was still exponential. For organizations protecting sensitive information over extended periods, this presents a significant operational challenge. A commitment to data security spanning twenty years necessitates accounting for generations of mathematical research, AI systems, and computing hardware. Captured traffic containing information that could be used to reconstruct an encryption key after a future breakthrough represents a persistent threat, enabling an attacker to exploit that vulnerability indefinitely. This is the core of the “Harvest Now, Decrypt Later” threat model, which is demonstrably global and remote. An algorithm upgrade protects future communications, but cannot retroactively secure previously intercepted data. Addressing this requires a shift in architectural thinking. A system’s security should be evaluated by the combinations of failures required to expose its data, rather than relying on layered cryptographic assumptions with a common failure point. Distributing sensitive material, separating security functions, and limiting data retention can significantly alter the attacker’s requirements. The goal is to make industrial-scale exploitation unviable, forcing adversaries to focus on individual devices or files, increasing both cost and risk. Qrypt’s BLAST approach exemplifies this principle, with communicating endpoints generating independent symmetric encryption keys locally from quantum-derived random material. This separates key generation from the application carrying the encrypted data, mitigating the risks associated with key transmission and eliminating single points of failure. The security value of such an approach depends on a broader design. Critical questions concern who can access the inputs, which channels and services must remain protected, how coordination information is secured, and how long the underlying random material remains available. Bulk decryption is possible when the randomness used to create encryption keys is flawed, or the algorithm using them is broken. Flawed randomness represents an opportunity for any intelligence service, whether deliberately introduced or inadvertently created. Security dependencies must be explicit and validated in deployed configurations, or they quickly become security theater. Endpoint compromise, authentication, the symmetric cipher protecting the data and the entire stack still matter. Quantum entropy provides a foundation for key generation that ensures the most devastating decryption methods are useless, a guarantee that algorithms alone cannot provide when the key space is known or predictable. Security leaders can prioritize by secrecy lifetime, identifying information whose disclosure would remain damaging years after collection, including intellectual property, sensitive training data and strategic communications. Mapping shared failure points and prioritizing systems that minimize the impact of a single cryptographic break are essential steps. The calculus of risk is shifting, and a proactive, architecturally-sound approach to security is no longer optional, but a necessity in the age of rapidly advancing artificial intelligence. HAWK Attack Reveals AI’s Growing Cryptographic Threat This success, detailed in July 2026, exploited a previously unnoticed symmetry within HAWK’s lattice structure, substantially reducing estimated security, although larger parameter sets remained impractical to attack at the time. The incident emphasises a shift where AI isn’t merely a tool for cryptanalysis, but an active, autonomous explorer of mathematical vulnerabilities. The speed of this discovery highlights a critical vulnerability in current security planning, as organizations may face a shrinking window between identifying a theoretical weakness and a functional exploit. While larger parameter sets within HAWK initially resisted attack, the demonstration of AI’s ability to uncover previously unknown symmetries necessitates a broader approach to post-quantum migration than simply adopting new algorithms. Security leaders must now prioritize reducing the consequences of any cryptographic failure, acknowledging that even robust algorithms are susceptible to future breakthroughs. This requires a detailed inventory of all affected systems and a tested plan for rapid recovery, not just a promise to switch algorithms at some unspecified date. Reflects the growing concern about the accessibility of powerful attack tools. The fact that Kani’s theorem, published decades ago, proved important in breaking SIKE demonstrates that previously obscure mathematical concepts can suddenly become critical cybersecurity vulnerabilities. Years without a successful attack offer some reassurance, but cannot definitively prove that all relevant mathematical connections have been explored, as a conclusive mathematical proof of absolute security remains elusive. The current reliance on post-quantum cryptography algorithms is therefore predicated on a degree of uncertainty, demanding a proactive approach to risk mitigation. Several products relying on the same cryptographic assumption can create a false sense of security, masking a common failure point. Qrypt, a US quantum-secure encryption company founded in 2017, addresses this through distributed quantum key generation technology, using the BLAST protocol to allow endpoints to generate independent symmetric keys without the risks associated with key transmission. The company sources quantum random numbers through partnerships with Los Alamos National Labs, providing cloud-based quantum entropy services reaching 1.5 Gbps data rates. However, even robust architectural designs cannot fully address the threat of retroactive insecurity. This highlights the importance of cryptographic agility, the ability to rapidly switch algorithms, but also emphasises the need to consider the long-term implications of data storage. Storing encrypted data, while relatively inexpensive, presents a continuous risk, particularly given the increasing sophistication of AI-powered cryptanalysis. This is not merely a theoretical concern; intelligence agencies are already using these capabilities on a vast scale. The next useful theorem may already be published, and the speed at which it is discovered and exploited will likely be determined by the power of AI-assisted cryptanalysis. The era of mathematical zero days is upon us, demanding a fundamental shift in how we approach cybersecurity, prioritizing architectural resilience and minimizing the consequences of inevitable algorithmic failures. Harvest Now, Decrypt Later: Long-Term Data Exposure Risks The 1997 theorem of Ernst Kani, largely overlooked for 25 years, proved instrumental in dismantling the Supersonic Multivariates Isogeny Key Encapsulation protocol, demonstrating how previously established mathematical principles can suddenly become critical vulnerabilities in cybersecurity systems. This historical precedent is now acutely relevant as frontier AI systems gain the capacity to connect previously disparate mathematical concepts, transforming them into potent tools for cryptanalysis, not merely assisting human analysts. Security architects must anticipate a shrinking timeframe between the identification of a theoretical weakness and the development of a functional attack targeting the foundations of data protection, demanding a shift in long-term planning beyond addressing immediate vulnerabilities. Larger parameter sets also succumbed to the attack, highlighting the speed with which a promising algorithm can be compromised. This rapid breakdown emphasizes the need to move beyond simply replacing vulnerable algorithms and focus on minimizing the consequences should a replacement itself eventually fail. The implications extend beyond algorithmic strength, impacting the very architecture of data security. Organizations safeguarding sensitive information for decades are implicitly committing to a security posture that must withstand generations of mathematical advancements, AI capabilities, and computing power. Captured data, even if encrypted with currently robust algorithms, presents a continuous risk if an attacker can reconstruct the encryption key following a future breakthrough. This operational reality defines the “Harvest Now, Decrypt Later” threat, where data collection and eventual exploitation are temporally separated, potentially spanning years and occurring remotely on a global scale. “An algorithm upgrade protects subsequent communications,” notes Qrypt, “It cannot recall copies already held by someone else.” The increasing sophistication of AI further complicates this landscape. This capability, while initially presented in a purely mathematical context, has direct implications for cryptography. “This was just a warmup,” according to OpenAI, and a departure from recent messaging focused on the potential dangers of releasing new models. Intelligence agencies are already actively using these AI capabilities, accelerating the search for overlooked cryptographic weaknesses. While the extent of this activity remains undisclosed, the potential for covert exploitation is significant. Unlike many other research endeavors, the validity of a cryptographic break is instantly verifiable, creating a unique and urgent threat. This AI-assisted research strengthens the tools available for evaluating new cryptography, but simultaneously provides adversaries with another avenue for accessing sensitive data. A robust security plan must account for both scenarios, including the possibility that attackers will deliberately withhold discoveries for as long as possible. Emphasizing the strategic value of maintaining secrecy. The focus must shift from solely preventing initial compromise to minimizing the long-term consequences of data exposure. Qrypt’s BLAST approach exemplifies this principle, using distributed quantum key generation to separate key creation from the data itself, eliminating single points of failure outside the endpoint. Qrypt’s Quantum-Secure IPsec Gateway combines BLAST with post-quantum cryptography, illustrating a path toward strengthening both algorithmic resilience and key distribution methods. Mapping shared failure points and implementing robust cryptographic agility, with accurate inventories, tested replacement procedures, and measured recovery times, are essential steps. However, even excellent agility cannot fully address the challenge of retroactive insecurity. Source: https://www.qrypt.com/resources/the-next-cryptographic-break-may-already-be-in-the-library/ More like thisCybersecurityFujitsu will now resell KELA’s threat intelligence in JapanArtificial IntelligenceColumbia University fellow shares 20 years of security expertiseTechnology NewsSenate Commerce Committee backs Cruz-Warner bill to harden telecom networksQuantum SecurityCloudflare Details 6 Implementation Steps Beyond Quantum-Safe AlgorithmsStay currentSee today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals. Tags: Ivy Delaney Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing.
For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.
Tags
Source Information
Discussion
0 professional contributions
Sign in to join this professional discussion.
Be the first to add a constructive contribution.
