Vitalik is now trying to convince everyone that lattices are bad because he is bag-holding too much hash-based crypto research can't back out. The case against lattices is the GNFS story, a.k.a. a hunch about "structure," and a multiplier pulled out of thin air. None of it has ever held up in the last few decades.
The factoring analogy is wrong. The number field sieve didn't come from generic cleverness. It came from very specific arithmetic -> smooth numbers, factor bases, relations stitched together by linear algebra into a congruence of squares. If you claim lattices have a GNFS hiding in the closet, you have to name what plays that role. "Structure" names nothing. The sieve was finished by 1993, and RSA sizes have barely moved in the thirty years since, so the lesson of factoring is that the skeletons ran out. Even the formula in the post is wrong. GNFS is exp(O(n^(1/3) (log n)^(2/3))), and if you're going to size parameters by analogy, you could at least get the analogy's complexity right.
Lattices had their sieve era decades ago. LLL in 1982, BKZ, pruned enumeration, sieving at 2^0.415n in 2008 and 2^0.292n in 2016. Every one of those was priced into parameters the moment it appeared. ML-KEM and ML-DSA are sized against exactly these attacks with a cost model that hands the attacker free memory and drops polynomial factors. The post talks as if nobody has ever seriously looked at lattices. Forty years of the best people in the field moved is the constant in the exponent.
The post also skips the one thing lattices have that GGEV and Peikert proved: breaking random LWE or SSIS instances at the right parameters solves approximate shortest-vector problems on every lattice of that dimension. A "skeleton" for plain LWE wouldn't be some clever trick for one family. It's a theorem for one of the most attacked problems in computer science. SHA-256 has no theorem like that. Its security is that nobody has broken it yet, which is exactly the standard the post refuses
to extend to lattices.
If you actually want to worry about structure in lattices, then look at the algebra of rings and ideal lattices. Cramer, Ducas, Peikert, and Regev (2016) and Cramer, Ducas, and Wesolowski (2017) gave quantum attacks on Ideal-SVP in cyclotomic fields. Albrecht, Bai, Ducas, and Kirchretched NTRU. Those results killed real schemes, and none of them touch ML-KEM or ML-DSA, which are module schemes with small moduli. Ducas, Plançon, and Wesolowski showed the quantum ideal attack does worse than plain BKZ at every dimension, applied the structure, measured how far the attacks reach, standardized outside their range, kept FrodoKEM with no ring at all, and added HQC in 2025 so KEMs don't rest on lattices alone. Vitalik is either unaware of this or hash-crypto bagholding is causing citation amnesia.
Then there's the claim that hashes are "intended" to have no structure, as if intent were a security proof. Differential cryptanalysis destroyed both MD5 and SHA-1 by attacking their round functions, with no help from P = NP. Of every family he lists, hashes are the only one whose deployed primitives have actually been broken. And the hash-only roadmap he's defending runs on Poseidon and Poseidon2, low-degree polynomial maps over small prime fields, built specifically to be easy to express algebraically. They are the most algebraically structured hashes anyone has ever put into production. Gröbner-basis and interpolation attacks are an active research area, and the Ethereum Foundation even funded a cryptanalysis bounty on Poseidon because of it. If AI is going to eat structure, Poseidon gets eaten long before Module-LWE.
The proof systems are no better. FRI, STIR, and WHIR at aggressive parameters rest on Reed-Solomon proximity-gap conjectures nobody has proven, and Fiat-Shamir is argued in the random oracle model. That's what "hash-only" actually means in practice. And "we'd pad the round count first" gives the game away, because extra rounds only defend against structure. He's admitting the structure is there.
The theory gets mangled too. Impagliazzo and Rudich is a black-box separation about proof techniques. It is not a theorem that public-key encryption "needs structure," and Merkle's puzzles already give hash-only key agreement with a quadratic gap, which Barak and Mahmoody showed is optimal in that model. "P ≠ NP so hashes are safe" is wrong as well, because P ≠ NP doesn't imply one-way functions exist, let alone that SHA-256 is one. That gap is the entire subject of Impagliazzo's five worlds. And the claim that an object with zero known structures is safer than one with exactly three is a probability claim with no underlying probability model for generic prime-field elliptic curves; the record runs the other way: every subexponential ECDLP attack since 1985 needed a special curve; everyone identified and excluded it, and Shoup's generic-group bound says precisely what a new attack would have to exploit. Nobody has found one in forty years.
"Multiply key sizes by ten" is numerology. Lattice attack cost goes like 2^(c·β). A better constant means you scale dimension by c/c', so a 20 percent improvement costs you about 25 percent more dimension, not 10x. A subexponential break means no multiplier saves you, because 10^n is still subexponential. Neither case gives you ten. Bytes aren't even a security parameter, since raising the modulus at fixed noise can make LWE easier. Parameter selection is a complexity formula set against a security target, and this post contains no formula.
"AI will deliver fifty years of math in two years" isn't a threat model. It names no algorithm or cost, and it can never be falsified, because every year without a break is just "not yet." It also cuts against hashes at least as hard as against lattices, and the post never explains why it shouldn't.
The field already has a working process for extraordinary claims. In 2024, a preprint claimed a quantum polynomial-time algorithm for LWE, and the bug was found in about ten days. Rainbow and SIKE fell on laptops during the NIST process, under the same public scrutiny that let the lattice schemes survive. An AI-found attack follows the same process: check it, run it through the estimators, and reparameterize. Abandoning the most studied post-quantum family before an attack exists is panic.
And the advice is actively dangerous outside of crypto Twitter. He concedes public-key encryption can't be avoided, then tells TLS, Tor, VPN, and messaging operators to get "much more paranoid" about the only post-quantum KEM that is actually deployed. Harvest-now-decrypt-later is happening right now, and hybrid ML-KEM, already shipping in browsers and messengers, is the defense. Spreading doubt about it, or bloating it tenfold until handshakes break, keeps traffic on classical crypto longer, which is the outcome he says he's worried about. "Send encrypted notes offchain through a third party" fixes nothing, because delivering to someone you'venever spoken to still needs public-key encryption, and now you've added a trusted party that sees your metadata and can drop your messages. Lumping ML-DSA and FHE into one bucket shows a weak grasp of both, since they live in completely different parameter regimes with different attacks.
Use hash-based signatures where they fit; the IETF has worked on XMSS for years, and there have been many great advancements. They are an algebraic dead end, however. You can't easily do the things we treasure in the elliptic-curve world.
Security engineering means naming the attack, costing it, and sizing the fix within the context of broader business and technological objectives. Vitalik never does this. He writes these damn posts that convince lots of engineers to abandon incredibly important research, and then we have to stumble back to it after years of false starts: Plasma, Ethereum 2.0, Casper, Accounts, etc etc etc. Now we are going to attack Lattices.
@covie_93 It’s designed to be a distraction, so headlines move away from all the other things going wrong with American domestic and foreign policy ahead of the midterms.
Yes, again, the snek chart.
Just a daily reminder how difficult it is for any project to reach this point. Snek survived multiple large drawdowns, the last one being the hardest at -95% from all time high. But that's what makes a project stronger for the next stage.
In the past 4 years, we cultivated what it means to be part of this. We focus on snek, stay in our lane, do what we do best. No false promises. No drama. One goal, make snek and $SNEK more valuable.
Minimize the failure risk. Maximize the potential return. Right now our odds are about as high as they've ever been. And it's feeling good.
@TuckerCarlson Carlson’s usual bullying overconfidence and quick-talking generalisations brilliantly undermined here by @Jacob_Rees_Mogg with smart, measured, informed debating skills and class.
@SLFMR1 Cardano is better now than it’s ever been, and will get better still. Peer reviewed, built by people who know how to develop a blockchain, iron clad community, scaling about to launch. It’s a solid bet for those who invest in quality.
September 2025: zcash:native was around $800M MC.
12 months later: $26B MC. A 3,100%+ move during a bear market. Nice!
October 2026: midnight-3:native is around $800M MC.
If midnight-3:native repeats that 3,100% move over the next 12 months, it would be at roughly $1.56 per NIGHT.
The difference?
Beyond the superior product, midnight-3:native will be making that move during a bull market.
So with that in mind, do you own enough midnight-3:native?
People in Cardano still don’t understand the kind of personality we have on our side.
Yes, Charles has an ego. So does almost everyone who builds at that level. If you want to operate where he operates, you can’t be polite to everyone and hope they don’t walk over you.
He just spoke at the UN. Not a side event. The United Nations. And he was received like someone who belongs there.
That should be treated as a national treasure for this ecosystem, not something to nitpick. His path is long. It’s also probably the most serious path we have toward the freedom this space keeps talking about.
Nobody else in Cardano is working at his level. Nobody.
A real bull run is coming in the next few years. When it does, we will want someone like Charles on our side.
Maybe it’s time the community started treating him that way.
#Cardano $ADA #UN #Crypto