Charles Hoskinson Disputes Vitalik Buterin’s Warning Against Lattice Cryptography
Cardano founder Charles Hoskinson on October 9 rejected Vitalik Buterin’s warning that AI-accelerated math could weaken lattice-based cryptography. At stake is whether Ethereum’s hash-only roadmap rests on better evidence than the lattice schemes it avoids, and Hoskinson argues that it does not. In a lengthy post on X, Hoskinson challenged the mathematical reasoning behind Buterin’s earlier warning, arguing that the Ethereum co-founder has not identified a credible attack capable of breaking lattice-based cryptography. “The case against lattices is the GNFS story, a.k.a. a hunch about ‘structure,’ and a multiplier pulled out of thin air,” the Cardano founder wrote. Buterin’s argument draws on the history of integer factorization, where decades of research produced the General Number Field Sieve (GNFS), which made factoring large numbers far more efficient than initially expected. According to him, AI could discover comparable shortcuts for lattice problems, forcing developers to increase cryptographic parameters substantially. Hoskinson rebutted by mentioning that lattices have already been attacked for decades now, including in the LLL attack in 1982 and further optimization of lattice sieving. He also pointed out that two post-quantum cryptographic systems, namely ML-KEM and ML-DSA, have taken into account these attacks. He also challenged Buterin’s suggestion that hash-based cryptography is inherently safer because hashes lack exploitable mathematical structure. MD5 and SHA-1, Hoskinson noted, were both broken through attacks on their internal designs. He added that Poseidon and Poseidon2, hash functions used in Ethereum’s cryptographic research, are built from algebraic operations and have also attracted cryptanalysis research. “SHA-256 has no theorem like that. Its security is that nobody has broken it yet,” Hoskinson argued, disputing the idea that hash-based systems deserve greater confidence simply because no successful attack is known. The Cardano founder further rejected Buterin’s recommendation to multiply lattice-based key sizes by ten. In his view, parameter selection requires a specific attack-cost calculation, not a blanket multiplier based on a hypothetical breakthrough. As CryptoPotato reported yesterday, Buterin advised users against rushing to move funds from ECDSA-based wallets while warning that AI-assisted mathematical advances could threaten existing cryptographic assumptions sooner than expected. Ethereum’s lean roadmap increasingly favors hash-based signatures, including WOTS and SPHINCS+, where applicable. However, Buterin has acknowledged that
AI Analysis:
Disclaimer: This information is from public sources for reference only. Traceless does not guarantee accuracy.