- Cardano founder Charles Hoskinson criticized Ethereum co-founder Vitalik Buterin’s assessment of lattice-based cryptography after Buterin urged the industry to consider whether artificial intelligence could accelerate mathematical breakthroughs.
- Hoskinson warned that amplifying what he described as unsupported fears could delay post-quantum protections and leave more communications exposed to future decryption attempts.
- He said ML-KEM and ML-DSA reflect decades of research and have no known real-world attacks that call their security into question.
Cardano founder Charles Hoskinson criticized Ethereum co-founder Vitalik Buterin’s position on cryptographic risks posed by advances in artificial intelligence. Hoskinson said abandoning lattice-based schemes without evidence of new vulnerabilities could hinder the deployment of post-quantum protections.
The debate followed Buterin’s call for the industry to account for the possibility that AI could accelerate mathematical breakthroughs. Buterin also cautioned against rushing to move funds to new wallets and raised concerns involving ECDSA and other cryptographic approaches, including ML-DSA and fully homomorphic encryption, or FHE.
Hoskinson said Buterin’s position did not sufficiently reflect years of research into lattice-based cryptography. He cited the LLL and BKZ algorithms and sieving methods, which researchers have considered when evaluating the difficulty of attacking lattice-based schemes and selecting their security parameters.
According to Hoskinson, ML-KEM and ML-DSA were designed with known attacks in mind. He said any potential new attack should undergo the standard validation process, including estimates of its computational cost and an assessment of whether the schemes’ security parameters require adjustment.
Hoskinson also referred to research into quantum attacks against certain lattice variants. He said those findings had influenced assessments of specific schemes but did not demonstrate that similar methods could break ML-KEM or ML-DSA.
He further disputed the argument that hash-based cryptography is automatically safer because it lacks certain mathematical structures. Hoskinson pointed to the breaks of MD5 and SHA-1 and said hash functions used in modern proof systems also rely on cryptographic assumptions and carry potential risks.
Hoskinson warns of delays to post-quantum protections
Hoskinson said overstating concerns about lattice-based cryptography could complicate the deployment of ML-KEM, a key encapsulation mechanism used in post-quantum security.
He linked the issue to the risk of “harvest now — decrypt later” attacks, in which adversaries collect encrypted traffic in the hope of decrypting it in the future. Delaying post-quantum mechanisms, he said, could leave more communications protected by traditional cryptography.
Hoskinson did not dispute the use of hash-based signatures in appropriate scenarios. His criticism focused on proposals to abandon lattice-based cryptography without a specific attack and a quantitative assessment of its effectiveness.
He said cryptographic risks should be evaluated using specific attack algorithms, computational-cost estimates and well-supported security parameters, rather than assumptions that AI could accelerate mathematical breakthroughs over the next two years.
Hoskinson previously estimated the risk of a quantum threat to the cryptocurrency industry at more than 50%.
Source: Incrypted
