On October 9, Cardano founder Charles Hoskinson publicly challenged Ethereum co-founder Vitalik Buterin's warning regarding the potential for AI-accelerated mathematics to weaken lattice-based cryptography.
At issue is whether Ethereum's shift toward hash-only post-quantum solutions rests on solid empirical evidence. Hoskinson argued that Buterin has not identified a credible, concrete attack capable of breaking lattice schemes.
Debating Lattice Safety vs. Hash-Based Alternatives
Buterin's original warning drew analogies to historical integer factorization research, specifically the General Number Field Sieve (GNFS), which dramatically reduced the time required to break large RSA keys. Based on this history, Buterin suggested that AI could discover similar mathematical shortcuts for lattice problems, advising developers to increase cryptographic key sizes by 10 times or pivot to hash-based signatures such as WOTS and SPHINCS+.
In response to Vitalik Buterin's post-quantum AI warning, Hoskinson stated on X that "the case against lattices is the GNFS story, a.k.a. a hunch about 'structure,' and a multiplier pulled out of thin air."
Hoskinson pointed out that lattice structures have been rigorously cryptanalyzed for decades, citing the LLL attack developed in 1982 alongside continuous optimizations in lattice sieving. He noted that modern standardized post-quantum algorithms, such as ML-KEM and ML-DSA, were specifically engineered to withstand these known attack vectors.
Historical Vulnerabilities in Hash Functions
Hoskinson also rejected the assertion that hash-based primitives are inherently safer due to an absence of exploitable algebraic structure. He noted that legacy hash algorithms like MD5 and SHA-1 were eventually broken by exploiting internal design flaws. Furthermore, modern algebraic hash functions used in zero-knowledge research—including Poseidon and Poseidon2—are actively subjected to intensive cryptanalysis.
Addressing standard hashing algorithms, Hoskinson highlighted that "SHA-256 has no theorem like that. Its security is that nobody has broken it yet." His statement aligns with broader crypto security debates regarding AI and ECDSA.
Key Takeaways
- Hoskinson rejected Buterin's recommendation to multiply lattice-based key parameters by 10 without explicit attack calculations.
- Post-quantum standards ML-KEM and ML-DSA already account for historical mathematical vectors like the 1982 LLL attack.
- MD5 and SHA-1 demonstrate that hash-based protocols are not immune to architectural security failures.
Why It Matters
The debate highlights fundamental architectural divergences in how major blockchain ecosystems prepare for quantum computing risks. While Ethereum's research leans toward hash-based signatures to avoid structural assumptions, Cardano's leadership favors standardized lattice frameworks validated by organizations like NIST. Abandoning established standards based on speculative AI breakthroughs could needlessly inflate transaction payloads and impair network performance before verified vulnerabilities emerge.



