HAWK exits and McEliece parameters buckle under fresh attacks
An AI-assisted lattice reduction forces HAWK out of the NIST signature round while quasipolynomial results leave Classic McEliece's proposed sizes without defenders.
The post-quantum transition has long treated its remaining finalists as schemes that would mostly survive the last stretch of public scrutiny. That premise is fraying on two fronts at once. A lattice signature contender has left the NIST round after an AI-assisted key-recovery break, and the long-standing code-based favorite is watching its proposed parameter sets lose expert support under quasipolynomial attacks.
In late July Steve Weis posted to the pqc-forum an improved key-recovery attack on HAWK-n that reduces the problem to SVP in dimension n/2 + 1. In the gate-count model of AGPS'20 the attack lowers HAWK-512 key recovery from 2^150 to 2^108 and HAWK-1024 from 2^288 to 2^182. A practical end-to-end implementation recovered a HAWK-256 secret key in a few hours on a single server. Weis stated that the result "does not impact Falcon, ML-DSA, or other latticed-based schemes," and he thanked the HAWK team for verification help. He also made the provenance plain: the break "was found by Claude, with minimal technical guidance from people." Daniel Apon checked the claim independently and replied, "Nice. It checks out independently for me." Facing the collapsed margins, HAWK was withdrawn from the NIST signature competition.
The technical point is narrow and therefore easy to misread. The reduction exploits structure specific to HAWK rather than a generic lattice collapse, which is why Falcon and ML-DSA are carved out. Yet the process signal is wider. A lightly steered model produced a dimension-halving observation that had escaped earlier human review, the claim was treated as immediately checkable, and a NIST contender exited. For every remaining structured design the open question is no longer only whether a clever reduction exists, but how quickly the next one will surface and who will find it.
Code-based cryptography absorbed a parallel shock. Ashrujit Ghoshal, Yuval Ishai, Aayush Jain, and Nuozhou Sun posted work claiming a provable quasipolynomial-time distinguisher for Classic McEliece public keys from random bytes, together with a heuristic quasipolynomial decryption path. Demi Marie Obenour laid out the immediate consequence: the claimed distinguisher complexity sits below security level 1 for every parameter set the Classic McEliece team had proposed. "The attack is currently impractical, but if it works, it seems quite devastating for Classic McEliece and for Goppa McEliece in general." Parameter changes can blunt it, she noted, but only by driving ciphertext sizes quadratic in the security parameter. "At this point, would Classic McEliece have any advantages over HQC or BIKE?"
Subsequent analysis sharpened the numbers. Related work put key-recovery costs for the proposed sets in the neighborhood of 2^94 to 2^102 bit operations, well under the stated Category 1, 3, and 5 targets and far below the scheme's own claimed figures of roughly 2^207 and 2^272 for the higher tiers. Christopher Peikert asked the direct question for those higher categories: given costs "far less than what those categories require," is it "fair to claim that Classic McEliece is broken" for the proposed parameters? Obenour's risk reading went further than any single paper. "Structural attacks on Classic McEliece are rapidly improving. Is there a strong reason to believe that the current attack is the best possible? I don't see one." Even a repaired parameter set would remain exposed to the next improvement; she saw little remaining application space once sizes balloon.
Cost-model skeptics pushed back on treating raw bit operations as decisive. D. J. Bernstein observed that one stated attack's real bottleneck is generating and routing on the order of 2^93 bits across many terabytes of RAM, a regime that does not map cleanly onto optimized AES attack hardware. Steve Weis corrected an n = 2^m assumption, published revised tables, and gave concrete larger examples: (23, 8192, 96) for about 2^192 runtime at 1.58 MiB public keys, and (32, 16384, 128) for 2^269 at 6 MiB. Jacob Alperin-Sheriff found the interactive comparisons useful precisely because they show the new structural attacks sitting complementary to information-set decoding. The disagreement is therefore twofold: whether the mathematics holds, and which resource model should govern NIST category claims when memory movement dominates arithmetic.
A third episode briefly threatened lattices more broadly and then receded. A claimed polynomial-time quantum algorithm for the dihedral coset problem raised the possibility of structure-independent lattice breaks. Markku-Juhani O. Saarinen reported that central lemmas failed as written; Aparna Gupte, Seyoon Ragavan, and Mark Zhandry argued the algorithm discards information that leaves the secret statistically hidden. John Preuß Mattsson used the scare to caution against presenting FrodoKEM as the default conservative choice and instead urged an ML-KEM plus HQC hybrid for diversification across hardness assumptions. Had the DCP claim survived it would have touched commutative group-action isogenies, not SQIsign or MIKE. The claim did not survive, yet it underscored the same pattern: margins are being tested faster than integration schedules like.
HAWK is gone from the signature track. Falcon and ML-DSA are outside the specific HAWK reduction, but the discovery method is now public. Classic McEliece's submitted parameters no longer command confidence from several active participants, and restoring margin appears to erase the size edge that justified the design against HQC and BIKE. Hybrid recommendations keep surfacing for exactly that reason. Isogeny NIKE work such as MIKE has already enlarged primes after separate cryptanalysis, another reminder that every family is adjusting under pressure.
What is unresolved is not the perfection of any one eprint. It is whether the schemes still carrying the transition rest on hardness assumptions whose attack surface is adequately mapped, and whether evaluation can absorb AI-accelerated and quasipolynomial advances without repeatedly discarding candidates after implementers have begun real integration. Diversification and larger margins look inexpensive next to another late withdrawal. The parameter tables and cost models remain under active, line-by-line dispute.