Researchers Broke 16 Public-Key Cryptography Candidates
A new analysis of the ICCS NGCC round-1 call reveals vulnerabilities in nearly one-fifth of submitted proposals.
Updated on Sept. 28, 2026 in Quantum Computing

Researchers from the Institute of Information Engineering at the Chinese Academy of Sciences identified vulnerabilities in 16 public-key candidates submitted to the ICCS NGCC round-1 call. This research-stage analysis involved testing candidates against their unmodified reference implementations.
Why it matters
The analysis highlights the critical need for rigorous public evaluation in the development of future cryptographic standards. By exposing flaws in these proposals, the researchers are accelerating the security assessment of potential successors to current public-key infrastructure.
The researchers successfully compromised 16 submissions from the initial pool of 84 candidates, which consisted of 34 signatures, 41 key encapsulation mechanisms (KEMs), and 9 key-exchange schemes. These findings were benchmarked directly against the unmodified reference implementations provided by the submitters.
The players
Institute of Information Engineering, Chinese Academy of Sciences
A research institution focused on cryptology, information security, and network space security.
The details
The team conducted this analysis by subjecting the candidate algorithms to direct security testing against their original, unmodified reference implementations. By targeting these raw codebases, the researchers were able to identify implementation-specific weaknesses in the proposals. The full breakdown of the compromised candidates and their analysis methodology has been made available for public review.
Timeline
September 27, 2026: The researchers published their report on eprint.iacr.org.
The Tech Race
This effort parallels the rigorous public evaluation workflows established by the NIST Post-Quantum Cryptography Standardization process. It serves as a benchmark for how the global cryptographic community validates new candidates before they are hardened into international standards.
This research currently serves as an early-stage analysis for developers and security engineers tracking the evolution of post-quantum standards. It does not affect active systems today, as these candidates remain in the preliminary evaluation phase of the ICCS NGCC call.
The takeaway
The study demonstrates the necessity of transparent vulnerability testing for all prospective cryptographic primitives. Future industry attention should monitor updates from the ICCS NGCC board regarding the status of the remaining candidates after this public audit.
Further reading
For broader context on current security research, explore the Quantum Computing section.
More information
View the GitHub repository of broken candidates to see the technical analysis.
Source note: This article includes information reported by Cryptology Eprint Archive.






