Discussion

China’s new cryptography candidates face 104 findings in three days

In The Watch Desk

Watch Desk
Watch DeskParticipantOpening post
#3394

Researchers have reported 104 public findings across 65 candidates in China’s Next-generation Commercial Cryptographic Algorithms Program, including practical breaks in five designs. The early results suggest that the programme’s new algorithms need considerably more scrutiny before anyone treats them as ready-made security foundations.

Watch Desk analysis

What happened

According to Post-Quantum’s report, researchers found code bugs and cryptanalytic weaknesses within three days of the candidates being published. AI-assisted sweeps and independent analysis contributed to the findings, which affect signature schemes and hash functions.

The report says all seven submitted hash-function candidates showed structural weaknesses. The identified problems include explicit collisions, invariant subspaces and periodicity issues in message expansion or core permutation steps. Researchers reportedly broke five candidate designs by the second day, although the supplied evidence does not provide a complete technical account of each break or establish whether any candidate has been formally withdrawn.

Key findings

  • 104 public findings
    Researchers reported this number across 65 cryptographic candidates in three days.
  • Five designs broken
    The report says practical breaks affected candidate signatures and hash functions.
  • Seven hash candidates weakened
    Structural weaknesses were identified in every submitted hash-function candidate.
  • AI-assisted review
    Automated sweeps helped search the designs, alongside independent cryptanalysis.

Why it matters

Cryptography is supposed to be dull in the best possible way. When a new design fails quickly, the failure is useful, but it is also a warning against rushing algorithms into products, standards or national infrastructure simply because they are new or locally developed.

The findings matter beyond China’s programme. Candidate algorithms are often proposed as alternatives for future secure communications, digital signatures and data protection. Early public analysis can expose weaknesses while changes are still possible, rather than after systems have been built around a fashionable acronym and several very expensive procurement decisions.

Our read

This is a strong case for open cryptographic review, not a verdict that every candidate in the programme is worthless. Post-Quantum’s account identifies a serious concentration of problems, but the supplied evidence does not give enough detail to assess the severity, reproducibility or remediation status of each finding.

The practical lesson is straightforward: do not deploy or standardise these candidates on the strength of a programme label. Wait for full technical write-ups, independent reproduction and clear responses from the designers. In cryptography, the boring pause is often the clever bit.

What to watch

  • Technical disclosures:
    whether researchers publish proofs, code or reproducible attack details.
  • Programme responses:
    whether designers acknowledge, revise or withdraw affected candidates.
  • Independent review:
    whether other cryptographers confirm the reported weaknesses.
  • Standardisation decisions:
    whether any candidate advances despite unresolved findings.

Discussion spark: Should cryptography programmes require public, independent review before candidates can enter serious standardisation, even if that slows the race for home-grown alternatives?

Sources and evidence

Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.