September 24, 2025
Author(s)
Thai Hung LE, Maxime Bros, Jacob Lichtinger, Brice Minaud, Ray Perlner, Daniel Smith-Tone, Cristian Valenzuela
… the security of SNOVA-I ($(v,o,\ell)=(24,5,4)$) down to $94$ bits of security when the previous attack was at $160$ … attack is that all parameters of SNOVA updated for Round 2 of NIST Standardization are now broken. …