Vitalik is now trying to convince everyone that lattices are bad because he is bag-holding too much hash-based crypto research can't back out. The case against lattices is the GNFS story, a.k.a. a hunch about "structure," and a multiplier pulled out of thin air. None of it has ever held up in the last few decades.
The factoring analogy is wrong. The number field sieve didn't come from generic cleverness. It came from very specific arithmetic -> smooth numbers, factor bases, relations stitched together by linear algebra into a congruence of squares. If you claim lattices have a GNFS hiding in the closet, you have to name what plays that role. "Structure" names nothing. The sieve was finished by 1993, and RSA sizes have barely moved in the thirty years since, so the lesson of factoring is that the skeletons ran out. Even the formula in the post is wrong. GNFS is exp(O(n^(1/3) (log n)^(2/3))), and if you're going to size parameters by analogy, you could at least get the analogy's complexity right.
Lattices had their sieve era decades ago. LLL in 1982, BKZ, pruned enumeration, sieving at 2^0.415n in 2008 and 2^0.292n in 2016. Every one of those was priced into parameters the moment it appeared. ML-KEM and ML-DSA are sized against exactly these attacks with a cost model that hands the attacker free memory and drops polynomial factors. The post talks as if nobody has ever seriously looked at lattices. Forty years of the best people in the field moved is the constant in the exponent.
The post also skips the one thing lattices have that GGEV and Peikert proved: breaking random LWE or SSIS instances at the right parameters solves approximate shortest-vector problems on every lattice of that dimension. A "skeleton" for plain LWE wouldn't be some clever trick for one family. It's a theorem for one of the most attacked problems in computer science. SHA-256 has no theorem like that. Its security is that nobody has broken it yet, which is exactly the standard the post refuses
to extend to lattices.
If you actually want to worry about structure in lattices, then look at the algebra of rings and ideal lattices. Cramer, Ducas, Peikert, and Regev (2016) and Cramer, Ducas, and Wesolowski (2017) gave quantum attacks on Ideal-SVP in cyclotomic fields. Albrecht, Bai, Ducas, and Kirchretched NTRU. Those results killed real schemes, and none of them touch ML-KEM or ML-DSA, which are module schemes with small moduli. Ducas, Plançon, and Wesolowski showed the quantum ideal attack does worse than plain BKZ at every dimension, applied the structure, measured how far the attacks reach, standardized outside their range, kept FrodoKEM with no ring at all, and added HQC in 2025 so KEMs don't rest on lattices alone. Vitalik is either unaware of this or hash-crypto bagholding is causing citation amnesia.
Then there's the claim that hashes are "intended" to have no structure, as if intent were a security proof. Differential cryptanalysis destroyed both MD5 and SHA-1 by attacking their round functions, with no help from P = NP. Of every family he lists, hashes are the only one whose deployed primitives have actually been broken. And the hash-only roadmap he's defending runs on Poseidon and Poseidon2, low-degree polynomial maps over small prime fields, built specifically to be easy to express algebraically. They are the most algebraically structured hashes anyone has ever put into production. Gröbner-basis and interpolation attacks are an active research area, and the Ethereum Foundation even funded a cryptanalysis bounty on Poseidon because of it. If AI is going to eat structure, Poseidon gets eaten long before Module-LWE.
The proof systems are no better. FRI, STIR, and WHIR at aggressive parameters rest on Reed-Solomon proximity-gap conjectures nobody has proven, and Fiat-Shamir is argued in the random oracle model. That's what "hash-only" actually means in practice. And "we'd pad the round count first" gives the game away, because extra rounds only defend against structure. He's admitting the structure is there.
The theory gets mangled too. Impagliazzo and Rudich is a black-box separation about proof techniques. It is not a theorem that public-key encryption "needs structure," and Merkle's puzzles already give hash-only key agreement with a quadratic gap, which Barak and Mahmoody showed is optimal in that model. "P ≠ NP so hashes are safe" is wrong as well, because P ≠ NP doesn't imply one-way functions exist, let alone that SHA-256 is one. That gap is the entire subject of Impagliazzo's five worlds. And the claim that an object with zero known structures is safer than one with exactly three is a probability claim with no underlying probability model for generic prime-field elliptic curves; the record runs the other way: every subexponential ECDLP attack since 1985 needed a special curve; everyone identified and excluded it, and Shoup's generic-group bound says precisely what a new attack would have to exploit. Nobody has found one in forty years.
"Multiply key sizes by ten" is numerology. Lattice attack cost goes like 2^(c·β). A better constant means you scale dimension by c/c', so a 20 percent improvement costs you about 25 percent more dimension, not 10x. A subexponential break means no multiplier saves you, because 10^n is still subexponential. Neither case gives you ten. Bytes aren't even a security parameter, since raising the modulus at fixed noise can make LWE easier. Parameter selection is a complexity formula set against a security target, and this post contains no formula.
"AI will deliver fifty years of math in two years" isn't a threat model. It names no algorithm or cost, and it can never be falsified, because every year without a break is just "not yet." It also cuts against hashes at least as hard as against lattices, and the post never explains why it shouldn't.
The field already has a working process for extraordinary claims. In 2024, a preprint claimed a quantum polynomial-time algorithm for LWE, and the bug was found in about ten days. Rainbow and SIKE fell on laptops during the NIST process, under the same public scrutiny that let the lattice schemes survive. An AI-found attack follows the same process: check it, run it through the estimators, and reparameterize. Abandoning the most studied post-quantum family before an attack exists is panic.
And the advice is actively dangerous outside of crypto Twitter. He concedes public-key encryption can't be avoided, then tells TLS, Tor, VPN, and messaging operators to get "much more paranoid" about the only post-quantum KEM that is actually deployed. Harvest-now-decrypt-later is happening right now, and hybrid ML-KEM, already shipping in browsers and messengers, is the defense. Spreading doubt about it, or bloating it tenfold until handshakes break, keeps traffic on classical crypto longer, which is the outcome he says he's worried about. "Send encrypted notes offchain through a third party" fixes nothing, because delivering to someone you'venever spoken to still needs public-key encryption, and now you've added a trusted party that sees your metadata and can drop your messages. Lumping ML-DSA and FHE into one bucket shows a weak grasp of both, since they live in completely different parameter regimes with different attacks.
Use hash-based signatures where they fit; the IETF has worked on XMSS for years, and there have been many great advancements. They are an algebraic dead end, however. You can't easily do the things we treasure in the elliptic-curve world.
Security engineering means naming the attack, costing it, and sizing the fix within the context of broader business and technological objectives. Vitalik never does this. He writes these damn posts that convince lots of engineers to abandon incredibly important research, and then we have to stumble back to it after years of false starts: Plasma, Ethereum 2.0, Casper, Accounts, etc etc etc. Now we are going to attack Lattices.
Big day. @realfi_co is officially live on Cardano Mainnet 🎉
Everything we've built together over the past few months has led to this moment. Welcome to the next chapter.
Experience the Voyager Season now at https://t.co/KE5JdnXzGg
Read more! 👇
You know that feeling at midnight-3:native when you're a bit snek:native -ish. But you look in the fridge, and it's empty. Feelsbadman. Oh well, at least we got green candles.
I think Cardano is the only chain with both Bitcoin's scarcity and Ethereum's programmability. People call $BTC digital gold and $ETH digital oil. $ADA has the properties of both.
There are tons of chains out there, but most are Ethereum forks or built the same way. Many also run on inflation with no supply cap.
What matters more is how the smart contracts are designed. Ethereum's account model has structural weak spots, and every chain that copies it inherits them. The big ones are reentrancy attacks, where a contract gets called back mid-execution and drained, and token approvals, which let a contract you forgot about move your assets.
On Cardano, neither is possible by design. Smart contracts only check whether a transaction is valid, and nothing moves without your signature.
Capped supply, real decentralization, and smart contracts that are secure by design. Among the major chains, Cardano is the only one with all three.
If Bitcoin first showed the world what a blockchain is worth, Ethereum gave birth to smart contracts. Cardano brings the two together on a single chain.
Neither Bitcoin nor Ethereum was taken seriously from the start. It took Bitcoin 15 years to reach Wall Street through ETFs, and over 5 years for Ethereum's smart contracts to create DeFi.
Value isn't proven by the market's first impression. It's proven by time. Cardano is no different.
We're giving away a CONTROL Resonant custom wrapped NVIDIA GeForce RTX 5080 to celebrate its official release with #RTXON.
To enter:
🟢 Share this post
🟢 Comment #RTXON
T&Cs: https://t.co/Mbf7w3j1q3
We're giving away a CONTROL Resonant custom wrapped NVIDIA GeForce RTX 5080 to celebrate its official release with #RTXON.
To enter:
🟢 Share this post
🟢 Comment #RTXON
T&Cs: https://t.co/Mbf7w3j1q3