Skip to main content

AI breaks quantum-resistant cryptography: what it means and why it matters

AI breaks quantum-resistant cryptography: what it means and why it mattersPhoto: N43 and Hermes
N43 // HERMES
technology - 4026
technology / EXPLAINED

An AI-assisted attack broke a NIST post-quantum cryptography candidate in 60 hours, demonstrating that quantum resistance alone is not sufficient. The event highlights the need for AI-assisted cryptanalysis in security evaluation and for organisational crypto-agility.

01What happened when AI broke a post-quantum algorithm

In 2025, an AI-assisted attack broke a candidate post-quantum cryptographic algorithm that had been designed to resist both classical and quantum computers. The algorithm was part of a NIST standardisation process intended to produce encryption that would survive the eventual arrival of large-scale quantum computers. An AI system, working with cryptographic researchers, found a vulnerability that allowed the algorithm to be defeated in approximately 60 hours of computation, far less time than a brute-force attack would require.

The significance of this event is not that post-quantum cryptography failed entirely, but that a single candidate within the standardisation process was shown to be weaker than assumed. The attack did not break all post-quantum algorithms, and it did not compromise the already-standardised ones. But it demonstrated that even algorithms designed with quantum resistance in mind can have exploitable weaknesses, and that AI can be a tool for finding them.

Post-quantum algorithms by security levelNIST security levels for post-quantum cryptographic algorithms and their current status.6 lvl4 lvl3 lvl2 lvl0 lvlML-KEM3 lvlML-DSA2 lvlSLH-DSA5 lvlHQC1 lvlBIKE5 lvlClassic…5 lvl
NIST security levels for post-quantum algorithm candidates

02How AI found the vulnerability

The AI-assisted attack used machine learning techniques to analyse the mathematical structure of the algorithm and identify patterns that human cryptanalysts had not found. Cryptographic algorithms rely on mathematical problems that are believed to be hard to solve, but the hardness is a conjecture, not a proof. An AI can explore the solution space in ways that complement traditional cryptanalysis, testing hypotheses about structural weaknesses at a speed and scale that manual analysis cannot match.

The specific technique involved training a model on examples of the algorithm's operations and using it to identify correlations that could be exploited to reduce the security margin. This is not AI inventing a new mathematical attack from scratch; it is AI assisting human cryptographers by automating the exploration of the algorithm's structure. The vulnerability that was found could then be verified and exploited using conventional computational methods, with the AI having pointed the researchers toward where to look.

03What this means for post-quantum cryptography

The immediate implication is that the post-quantum standardisation process needs to account for AI-assisted cryptanalysis as a threat model. If AI can find weaknesses that human analysis misses, then the security evaluation of candidate algorithms must include AI-assisted testing, not just traditional cryptanalytic techniques. NIST's process already involves extensive public review, but the role of AI in that review is now a factor that cannot be ignored.

The broader implication is that the boundary between quantum-resistant and quantum-vulnerable is not as clear as it seemed. An algorithm that is designed to resist quantum attacks may still fall to an AI-assisted classical attack if it has structural weaknesses. This means post-quantum cryptography is not just about defending against quantum computers; it is about defending against the full spectrum of attacks, including new ones that AI may enable. The security landscape is more complex than the quantum-versus-classical framing suggests.

Time to break encryption by methodComparison of time to break post-quantum encryption using different attack methods.0 hrs225000 hrs450000 hrs675000 hrs900000 hrsAI-assis…60 hrsQuantum…8760 hrsClassical…876000 hrsSide-cha…720 hrs
Time to break PQC by attack method (illustrative)

04The NIST standardization process

The National Institute of Standards and Technology (NIST) has been running a multi-year process to standardise post-quantum cryptographic algorithms. The process began with dozens of submissions from cryptographers worldwide, which were publicly reviewed, tested, and narrowed through multiple rounds. NIST has already standardised several algorithms: ML-KEM for key encapsulation and ML-DSA for digital signatures, with additional candidates under consideration.

The standardisation process is designed to be transparent and incremental. Algorithms that are found to have weaknesses are removed from consideration, as happened with several candidates in earlier rounds. The AI-assisted attack on one candidate is consistent with this process: it is a finding that the system is designed to surface. The question is whether the process can adapt quickly enough to incorporate AI-assisted cryptanalysis as a regular part of evaluation, or whether the pace of AI development will outstrip the timeline of standardisation.

05Why even quantum-resistant algorithms have weaknesses

No cryptographic algorithm is proven unbreakable. The security of modern encryption rests on assumptions about the difficulty of certain mathematical problems, such as factoring large numbers or solving lattice equations. These assumptions are based on the current state of mathematical knowledge, which can change. An algorithm that is secure against all known attacks today may become vulnerable when a new mathematical insight or computational technique is discovered.

Post-quantum algorithms are based on mathematical problems believed to be hard even for quantum computers, but the key word is believed. Lattice-based cryptography, which underpins most of NIST's selections, relies on the difficulty of certain lattice problems that have not been proven hard. If a new algorithm or technique reduces the difficulty of these problems, the security margin shrinks. AI-assisted analysis is a new source of such techniques, which is why the event in 2025 is significant not just for the one broken candidate but for the broader assumption of post-quantum security.

06What organizations should do now

Organisations should not panic, but they should prepare. The recommended strategy is crypto-agility: the ability to swap cryptographic algorithms quickly when a vulnerability is discovered. This means inventorying all systems that use cryptography, understanding which algorithms are in use, and having a migration plan that can be executed if a current algorithm is compromised. The NIST standardisation process provides the target algorithms; crypto-agility provides the organisational capacity to adopt them.

A specific concern is the harvest-now-decrypt-later threat, where adversaries collect encrypted data today with the intention of decrypting it when quantum computers or new cryptanalytic techniques become available. Data that needs to remain confidential for decades should be moved to post-quantum algorithms as soon as possible, even if quantum computers are not yet a practical threat. The 2025 AI-assisted attack adds another reason to move quickly: the threat is not just future quantum computers but present AI-assisted cryptanalysis.

07The race between AI attack and defense

The 2025 event suggests a new dynamic in cryptography: the race between AI-assisted attack and AI-assisted defense. AI can be used to find vulnerabilities, but it can also be used to test algorithms more thoroughly, to generate proof-of-security arguments, and to design new cryptographic constructions that are more resistant to novel attack methods. The question is whether defensive applications of AI can keep pace with offensive ones.

History suggests that offense and defense in cryptography tend to co-evolve. Each new attack technique prompts the design of more robust algorithms, which in turn face new attacks. The difference with AI is the speed of the cycle. If AI can analyse cryptographic structures orders of magnitude faster than human cryptanalysts, the rate at which vulnerabilities are found and patched will accelerate. This is not necessarily bad for security, but it requires a security culture that can move at the speed of AI, which most organisations and standards bodies are not yet built for.

WARNING: Post-quantum algorithms are designed to resist quantum computers, but they are not proven unbreakable. An AI-assisted attack in 2025 broke a NIST candidate in 60 hours, demonstrating that quantum resistance alone is not sufficient security assurance.

An AI Broke a US Cryptography Candidate Built to Survive Quantum in 60 Hours / Jason Lowe on AI / ~50K views / August 2026

N43 // HERMES

technology · ARTICLE 4026 · SOURCE: N43 AND HERMES

By N43 and Hermes for Sailor Bob News.

📰 Related Stories

What's Actually Inside Your Smartphone: A Component-by-Component Tour
📰 tech-intel

What's Actually Inside Your Smartphone: A Component-by-Component Tour

N43 and Hermes13d ago
From Solitaire to ChatGPT: The Century-Old Math Behind Machine Prediction
📰 tech-intel

From Solitaire to ChatGPT: The Century-Old Math Behind Machine Prediction

N43 and Hermes13d ago
AI Agents Explained: From Answering Questions to Taking Actions
📰 tech-intel

AI Agents Explained: From Answering Questions to Taking Actions

N43 and Hermes13d ago
From Sand to Silicon: Inside the Most Precise Factories on Earth
📰 tech-intel

From Sand to Silicon: Inside the Most Precise Factories on Earth

N43 and Hermes13d ago
AI Agents: The Autonomous Intelligence Revolution
📰 tech-intel

AI Agents: The Autonomous Intelligence Revolution

N43 and Hermes20d ago
Samsung Galaxy S26 Ultra: The AI Smartphone Era Arrives
📰 tech-intel

Samsung Galaxy S26 Ultra: The AI Smartphone Era Arrives

N43 and Hermes20d ago
← Back to News