The algorithm that died in an hour
On the last day of July 2022, Wouter Castryck and Thomas Decru, mathematicians at KU Leuven in Belgium, published a ten-page paper that reduced a NIST post-quantum cryptography finalist to rubble. The algorithm — SIKE, short for Supersingular Isogeny Key Encapsulation — had survived four years of expert scrutiny and reached the competition’s final round. Their attack ran in roughly one hour on a single laptop core. The mathematics it used came from a theorem Ernst Kani had proved in 1997.
The irony was precise: a candidate chosen to protect data against future quantum computers, destroyed by very old mathematics running on commodity hardware.
Behind the competition was a dread that had been building since 1994. That year, Peter Shor at Bell Labs proved that a sufficiently large quantum computer could factor integers and compute discrete logarithms exponentially faster than any classical machine. RSA and elliptic-curve cryptography — the engines that secure email, banking, and the web — depend on exactly those hard problems. A quantum computer of sufficient scale would break them cleanly. Shor’s machine did not exist yet, but the algorithm did, and that was enough. The question was not whether to prepare; it was which replacement to trust.
In 2016, NIST issued a formal call for post-quantum cryptographic algorithms. Eighty-two submissions arrived from cryptographers across 25 countries — a controlled, adversarial, multi-year process in which the security community was invited to attack everything it could. The public structure was deliberate. The DES standard of 1976 had attracted suspicion over undisclosed NSA involvement in its design; the AES competition of the late 1990s had shown that open scrutiny produces more trustworthy results. NIST ran the same playbook: publish the candidates, let the world try to break them.
By July 2022, three rounds of analysis had narrowed the field. Four algorithms moved forward. Two came from the CRYSTALS suite — CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for digital signatures — built by a multinational team at KU Leuven, IBM, NXP Semiconductors, CWI Amsterdam, and Radboud University Nijmegen. Both rely on the hardness of problems over mathematical lattices, structures that quantum computers are not known to solve any faster than classical ones. FALCON and SPHINCS+ rounded out the quartet.
Then Castryck and Decru’s paper appeared. SIKE had been built on a different mathematical foundation: isogenies between elliptic curves. Their attack applied Kani’s 1997 glue-and-split theorem in a way no one had anticipated, and security level one of SIKE fell in about an hour. The scheme was withdrawn from the competition the same month. Two other candidates — including the Rainbow signature scheme — had already been broken earlier that year. The competition was working exactly as intended: better to fail under the scrutiny of thousands of mathematicians than under the pressure of a state adversary.
On August 13, 2024, NIST published three Federal Information Processing Standards: FIPS 203 (ML-KEM, the renamed Kyber), FIPS 204 (ML-DSA, the renamed Dilithium), and FIPS 205 (SLH-DSA, from SPHINCS+). The quantum computer capable of breaking RSA at scale still does not exist — estimates for a cryptographically relevant machine sit somewhere in the 2030s. But migration takes years, and governments and financial institutions are already replacing encryption infrastructure, one system at a time.
The threat is theoretical. The preparation is not.
Sources
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards — NIST — competition timeline, 82 submissions, algorithm names, August 13, 2024 publication date.
- NIST Post-Quantum Algorithm Finalist Cracked Using a Classical PC — SecurityWeek — Castryck and Decru’s attack on SIKE, timing, and its withdrawal from the competition.
- IBM-Developed Algorithms Announced as NIST’s First Post-Quantum Cryptography Standards — IBM Newsroom — IBM’s role in developing ML-KEM and ML-DSA; context on the 82 submissions from 25 countries.
- Dutch and Belgian Involvement in New Post-Quantum Cryptography Standard — Bits&Chips — CRYSTALS team members and their institutional affiliations.