Researchers have reported 104 public findings across 65 candidates in China’s Next-generation Commercial Cryptographic Algorithms Program, including practical breaks in five designs. The early results suggest that the programme’s new algorithms need considerably more scrutiny before anyone treats them as ready-made security foundations.
Watch Desk analysis
What happened
According to Post-Quantum’s report, researchers found code bugs and cryptanalytic weaknesses within three days of the candidates being published. AI-assisted sweeps and independent analysis contributed to the findings, which affect signature schemes and hash functions.
The report says all seven submitted hash-function candidates showed structural weaknesses. The identified problems include explicit collisions, invariant subspaces and periodicity issues in message expansion or core permutation steps. Researchers reportedly broke five candidate designs by the second day, although the supplied evidence does not provide a complete technical account of each break or establish whether any candidate has been formally withdrawn.
Key findings
- 104 public findings
Researchers reported this number across 65 cryptographic candidates in three days. - Five designs broken
The report says practical breaks affected candidate signatures and hash functions. - Seven hash candidates weakened
Structural weaknesses were identified in every submitted hash-function candidate. - AI-assisted review
Automated sweeps helped search the designs, alongside independent cryptanalysis.
Why it matters
Cryptography is supposed to be dull in the best possible way. When a new design fails quickly, the failure is useful, but it is also a warning against rushing algorithms into products, standards or national infrastructure simply because they are new or locally developed.
The findings matter beyond China’s programme. Candidate algorithms are often proposed as alternatives for future secure communications, digital signatures and data protection. Early public analysis can expose weaknesses while changes are still possible, rather than after systems have been built around a fashionable acronym and several very expensive procurement decisions.
Our read
This is a strong case for open cryptographic review, not a verdict that every candidate in the programme is worthless. Post-Quantum’s account identifies a serious concentration of problems, but the supplied evidence does not give enough detail to assess the severity, reproducibility or remediation status of each finding.
The practical lesson is straightforward: do not deploy or standardise these candidates on the strength of a programme label. Wait for full technical write-ups, independent reproduction and clear responses from the designers. In cryptography, the boring pause is often the clever bit.
What to watch
- Technical disclosures:
whether researchers publish proofs, code or reproducible attack details. - Programme responses:
whether designers acknowledge, revise or withdraw affected candidates. - Independent review:
whether other cryptographers confirm the reported weaknesses. - Standardisation decisions:
whether any candidate advances despite unresolved findings.
Discussion spark: Should cryptography programmes require public, independent review before candidates can enter serious standardisation, even if that slows the race for home-grown alternatives?
Sources and evidence
- China’s Next-Generation Crypto Candidates Drew 104 Public Findings in Three Days. Researchers Broke Five Designs on Day Two (23 September 2026, 11:58 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.