Cardano founder Charles Hoskinson says Vitalik Buterin’s warning about AI-driven mathematical breakthroughs could slow adoption of quantum-resistant cryptography. In an Oct. 9 post, Hoskinson defended lattice-based approaches, arguing that decades of research have accounted for known attacks and that abandoning them could narrow developers’ options.
Why it matters
Buterin has argued that AI could accelerate mathematical discoveries that weaken cryptography designed to resist quantum computers. Ethereum’s long-term “lean” roadmap has consequently moved toward hash-based signatures and proofs, rather than lattice-based designs. Hoskinson disputes the case against lattices, saying the analogy to advances in attacks on RSA does not demonstrate a comparable weakness in lattice cryptography.
The debate touches standards already adopted beyond crypto. The US National Institute of Standards and Technology standardized ML-KEM for key encapsulation and ML-DSA for digital signatures in 2024. Hoskinson says their security parameters reflect known attacks, and argues that changes should follow measurable improvements in attack methods rather than a blanket proposal to multiply key sizes by ten.
Market impact
The choice matters because the approaches serve different needs. Hash-based signatures can support quantum-resistant transaction authorization, while lattice techniques also enable key encapsulation and other cryptographic constructions used in encryption and privacy systems. Abandoning lattice research could limit tools available to developers building secure communications and privacy applications.
Hoskinson also cautioned against treating hash-based methods as immune to future discoveries. He cited past weaknesses in MD5 and SHA-1, while acknowledging that those failures do not establish vulnerabilities in modern constructions such as SHA-256. He also questioned research around Poseidon and Poseidon2, Ethereum-relevant hash functions used in zero-knowledge proofs. The disagreement leaves protocol developers weighing competing cryptographic risks, not a demonstrated break in either approach.
Frequently asked questions
-
Why does Hoskinson object to Buterin’s warning about lattice cryptography?
Hoskinson argues that decades of research have accounted for known attacks on lattice systems, and that discouraging their use could slow adoption of quantum-resistant protections.
-
Which cryptographic approaches does Ethereum’s long-term roadmap favor?
The article says Ethereum’s long-term “lean” roadmap has moved toward hash-based signatures and proofs rather than lattice-based designs.
-
What post-quantum standards did NIST adopt in 2024?
NIST standardized ML-KEM for key encapsulation and ML-DSA for digital signatures in 2024.
-
What different uses do lattice-based and hash-based cryptography support?
Hash-based signatures can support quantum-resistant transaction authorization. Lattice techniques also support key encapsulation and other constructions used in encryption and privacy systems.
-
Does the dispute show that modern hash-based cryptography has been broken?
No. Hoskinson cited historical weaknesses in MD5 and SHA-1 but did not claim those failures establish vulnerabilities in modern constructions such as SHA-256.
CryptoSlate