
この記事の要点
- ADA創設者ホスキンソン氏がブテリン氏の格子暗号批判に反論
- 格子暗号への不信拡大は耐量子移行の遅れを招くと警告
ホスキンソン氏、格子暗号批判に反論
カルダノ(ADA)創設者のチャールズ・ホスキンソン氏は2026年10月9日、イーサリアム(ETH)共同創設者ヴィタリック・ブテリン氏による格子暗号への懐疑的な見解に対し、自身のX(旧Twitter)投稿で反論しました。
ブテリン氏はAIの進歩によって格子暗号の未知の弱点が発見される可能性を懸念しており、ホスキンソン氏は40年以上にわたる攻撃研究と安全性評価の蓄積を根拠に、具体的な攻撃手法を示さない批判は不十分だと指摘しています。
さらにホスキンソン氏は、格子暗号への不信が広がることで、インターネット通信やメッセージングアプリなどの耐量子暗号への移行が遅れ、将来の量子コンピュータによる通信内容の解読リスクが高まる恐れがあると警告しました。
イーサリアムは量子コンピュータへの対策としてハッシュベースの署名・証明方式を重視しており、公式ロードマップでもleanXMSSやSLH-DSAなどを候補に挙げるなど、両氏の間では耐量子暗号の安全性評価や採用方針をめぐる見解の違いが表面化しています。
Vitalik is now trying to convince everyone that lattices are bad because he is bag-holding too much hash-based crypto research can’t back out. The case against lattices is the GNFS story, a.k.a. a hunch about "structure," and a multiplier pulled out of thin air. None of it has ever held up in the last few decades.
The factoring analogy is wrong. The number field sieve didn’t come from generic cleverness. It came from very specific arithmetic -> smooth numbers, factor bases, relations stitched together by linear algebra into a congruence of squares. If you claim lattices have a GNFS hiding in the closet, you have to name what plays that role. "Structure" names nothing. The sieve was finished by 1993, and RSA sizes have barely moved in the thirty years since, so the lesson of factoring is that the skeletons ran out. Even the formula in the post is wrong. GNFS is exp(O(n^(1/3) (log n)^(2/3))), and if you’re going to size parameters by analogy, you could at least get the analogy’s complexity right.
Lattices had their sieve era decades ago. LLL in 1982, BKZ, pruned enumeration, sieving at 2^0.415n in 2008 and 2^0.292n in 2016. Every one of those was priced into parameters the moment it appeared. ML-KEM and ML-DSA are sized against exactly these attacks with a cost model that hands the attacker free memory and drops polynomial factors. The post talks as if nobody has ever seriously looked at lattices. Forty years of the best people in the field moved is the constant in the exponent.
The post also skips the one thing lattices have that GGEV and Peikert proved: breaking random LWE or SSIS instances at the right parameters solves approximate shortest-vector problems on every lattice of that dimension. A "skeleton" for plain LWE wouldn’t be some clever trick for one family. It’s a theorem for one of the most attacked problems in computer science. SHA-256 has no theorem like that. Its security is that nobody has broken it yet, which is exactly the standard the post refuses
to extend to lattices.
If you actually want to worry about structure in lattices, then look at the algebra of rings and ideal lattices. Cramer, Ducas, Peikert, and Regev (2016) and Cramer, Ducas, and Wesolowski (2017) gave quantum attacks on Ideal-SVP in cyclotomic fields. Albrecht, Bai, Ducas, and Kirchretched NTRU. Those results killed real schemes, and none of them touch ML-KEM or ML-DSA, which are module schemes with small moduli. Ducas, Plançon, and Wesolowski showed the quantum ideal attack does worse than plain BKZ at every dimension, applied the structure, measured how far the attacks reach, standardized outside their range, kept FrodoKEM with no ring at all, and added HQC in 2025 so KEMs don’t rest on lattices alone. Vitalik is either unaware of this or hash-crypto bagholding is causing citation amnesia.
Then there’s the claim that hashes are "intended" to have no structure, as if intent were a security proof. Differential cryptanalysis destroyed both MD5 and SHA-1 by attacking their round functions, with no help from P = NP. Of every family he lists, hashes are the only one whose deployed primitives have actually been broken. And the hash-only roadmap he’s defending runs on Poseidon and Poseidon2, low-degree polynomial maps over small prime fields, built specifically to be easy to express algebraically. They are the most algebraically structured hashes anyone has ever put into production. Gröbner-basis and interpolation attacks are an active research area, and the Ethereum Foundation even funded a cryptanalysis bounty on Poseidon because of it. If AI is going to eat structure, Poseidon gets eaten long before Module-LWE.
The proof systems are no better. FRI, STIR, and WHIR at aggressive parameters rest on Reed-Solomon proximity-gap conjectures nobody has proven, and Fiat-Shamir is argued in the random oracle model. That’s what "hash-only" actually means in practice. And "we’d pad the round count first" gives the game away, because extra rounds only defend against structure. He’s admitting the structure is there.
The theory gets mangled too. Impagliazzo and Rudich is a black-box separation about proof techniques. It is not a theorem that public-key encryption "needs structure," and Merkle’s puzzles already give hash-only key agreement with a quadratic gap, which Barak and Mahmoody showed is optimal in that model. "P ≠ NP so hashes are safe" is wrong as well, because P ≠ NP doesn’t imply one-way functions exist, let alone that SHA-256 is one. That gap is the entire subject of Impagliazzo’s five worlds. And the claim that an object with zero known structures is safer than one with exactly three is a probability claim with no underlying probability model for generic prime-field elliptic curves; the record runs the other way: every subexponential ECDLP attack since 1985 needed a special curve; everyone identified and excluded it, and Shoup’s generic-group bound says precisely what a new attack would have to exploit. Nobody has found one in forty years.
"Multiply key sizes by ten" is numerology. Lattice attack cost goes like 2^(c·β). A better constant means you scale dimension by c/c’, so a 20 percent improvement costs you about 25 percent more dimension, not 10x. A subexponential break means no multiplier saves you, because 10^n is still subexponential. Neither case gives you ten. Bytes aren’t even a security parameter, since raising the modulus at fixed noise can make LWE easier. Parameter selection is a complexity formula set against a security target, and this post contains no formula.
"AI will deliver fifty years of math in two years" isn’t a threat model. It names no algorithm or cost, and it can never be falsified, because every year without a break is just "not yet." It also cuts against hashes at least as hard as against lattices, and the post never explains why it shouldn’t.
The field already has a working process for extraordinary claims. In 2024, a preprint claimed a quantum polynomial-time algorithm for LWE, and the bug was found in about ten days. Rainbow and SIKE fell on laptops during the NIST process, under the same public scrutiny that let the lattice schemes survive. An AI-found attack follows the same process: check it, run it through the estimators, and reparameterize. Abandoning the most studied post-quantum family before an attack exists is panic.
And the advice is actively dangerous outside of crypto Twitter. He concedes public-key encryption can’t be avoided, then tells TLS, Tor, VPN, and messaging operators to get "much more paranoid" about the only post-quantum KEM that is actually deployed. Harvest-now-decrypt-later is happening right now, and hybrid ML-KEM, already shipping in browsers and messengers, is the defense. Spreading doubt about it, or bloating it tenfold until handshakes break, keeps traffic on classical crypto longer, which is the outcome he says he’s worried about. "Send encrypted notes offchain through a third party" fixes nothing, because delivering to someone you’venever spoken to still needs public-key encryption, and now you’ve added a trusted party that sees your metadata and can drop your messages. Lumping ML-DSA and FHE into one bucket shows a weak grasp of both, since they live in completely different parameter regimes with different attacks.
Use hash-based signatures where they fit; the IETF has worked on XMSS for years, and there have been many great advancements. They are an algebraic dead end, however. You can’t easily do the things we treasure in the elliptic-curve world.
Security engineering means naming the attack, costing it, and sizing the fix within the context of broader business and technological objectives. Vitalik never does this. He writes these damn posts that convince lots of engineers to abandon incredibly important research, and then we have to stumble back to it after years of false starts: Plasma, Ethereum 2.0, Casper, Accounts, etc etc etc. Now we are going to attack Lattices.
— Charles Hoskinson (@IOHK_Charles) October 9, 2026
ヴィタリック氏は今、格子暗号は危険だと主張し、周囲を説得しようとしている。ハッシュベース暗号の研究に肩入れしすぎた結果、今さら引き返せなくなっているのではないか。
格子暗号を否定する根拠として持ち出されるのは、GNFSになぞらえた議論だ。「格子には何か未知の構造が隠れているはずだ」という推測と、根拠のはっきりしない安全性の倍率。そんな話ばかりで、ここ数十年、その主張を裏付ける成果は出ていない。
そもそも、整数の素因数分解と格子暗号を同列に扱うこと自体が間違っている。(後略)
量子開発と耐量子暗号で大統領令
格子暗号擁護と反論の3争点
GNFSとの比較は不適切と一蹴
ブテリン氏は、RSA暗号に対する一般数体篩法(GNFS)の進歩を例に挙げ、格子暗号にも未知の構造的な弱点が発見される可能性を指摘していました。
これに対しホスキンソン氏は、GNFSが平滑数や因子基底、線形代数を組み合わせた特定の数学的手法であることを説明し、格子暗号にも同様の弱点が存在すると主張するなら、その仕組みを明らかにすべきだと反論しています。
その根拠として同氏は、格子暗号への攻撃研究が1982年のLLLアルゴリズムからBKZ、枝刈り列挙、格子篩法へと発展し、発見された攻撃手法が暗号パラメータの設計に反映されてきた経緯を挙げました。
米国国立標準技術研究所(NIST)が策定した鍵カプセル化方式ML-KEM(FIPS 203)とデジタル署名方式ML-DSA(FIPS 204)も、既知の格子攻撃を前提に安全性が評価されており、ホスキンソン氏はこうした評価を踏まえずに未知の弱点を懸念する議論を批判しています。
「ハッシュ方式こそAI攻撃に脆弱」と指摘
格子暗号への批判に反論したホスキンソン氏は、ブテリン氏が重視するハッシュベースの暗号方式についても、安全性が保証されているわけではないと指摘しました。
その根拠として、ハッシュ関数のMD5やSHA-1が過去に暗号解析によって破られた事例を挙げ、数学的な構造が少ないとされる方式でも未知の弱点が発見される可能性があると主張しています。
同氏は、イーサリアムのゼロ知識証明関連で利用が検討されているPoseidonとPoseidon2にも言及し、これらは代数的な構造を持つため、AIによる新たな攻撃を懸念するなら格子暗号以上に警戒すべきだとの認識を示しました。
イーサリアム財団の暗号研究部門も、Poseidonを含むZK向けハッシュ関数を対象に総額20万ドルの暗号解析懸賞金プログラムを設けており、2025年の助成金報告でもPoseidonの代数的暗号解析に関する研究支援が公表されています。
「鍵サイズ10倍」に根拠なし
またホスキンソン氏は、ブテリン氏が提案した「鍵サイズを10倍にする」という対策についても、攻撃の計算量にもとづく根拠が示されていないと批判しています。
同氏によれば、格子暗号への攻撃コストは次元に対して指数的に増加するため、攻撃効率が20%改善した場合でも、必要な次元の増加は約25%で済むとしています。
仮に攻撃手法そのものが準指数時間へと大幅に改善された場合には、単純な鍵サイズの拡大では十分な防御策にならず、いずれのシナリオでも10倍という数字には合理的な根拠がないと説明しました。
ホスキンソン氏は、AIが短期間で数学研究を大幅に進歩させるというブテリン氏の予測についても、具体的な攻撃アルゴリズムや計算コストが示されていないと批判し、実証されていない脅威を理由に格子暗号の採用を見直すべきではないとの立場を示しています。
「ヘゴタ」の改修方針を公表
格子暗号をNISTが標準化、実装も加速
耐量子暗号をめぐっては、NISTが2024年8月に格子ベースのML-KEM・ML-DSAとハッシュベースのSLH-DSA(FIPS 205)を標準化し、2025年3月には異なる数学的手法を用いる符号ベースのHQCをML-KEMのバックアップ方式として選定しました。
民間でも格子ベースの耐量子暗号が実用化されており、GoogleはChromeのTLS通信でML-KEM系のハイブリッド鍵交換方式を採用し、Signalも耐量子鍵合意方式PQXDHに加えて、ML-KEMを利用するML-KEM Braidの技術仕様を公開しています。
こうした耐量子暗号の実装が進められている理由の一つに、将来の量子コンピュータによる復号を目的に、暗号化された通信データを現在のうちに収集する「ハーベスト・ナウ・デクリプト・レイター」と呼ばれる脅威があります。
ホスキンソン氏は、こうした通信保護の現状を踏まえ、実用化が進む格子暗号を根拠なく退けることに反対しており、今回の論争では未知の攻撃リスクをどこまで考慮し、既存の耐量子技術をどのように採用していくかという判断の違いが浮き彫りになっています。
関連の注目記事はこちら
Source:チャールズ・ホスキンソン氏X投稿 / ヴィタリック・ブテリン氏X投稿
サムネイル:AIによる生成画像

12 時間前
5













English (US) ·
Japanese (JP) ·