Cardano founder Charles Hoskinson criticized Ethereum co-founder Vitalik Buterin’s position on the risks AI development poses to cryptography. He called the arguments against lattice-based cryptographic schemes insufficiently substantiated and said that abandoning them without concrete evidence of new vulnerabilities could harm the industry’s development.
The discussion began after Buterin urged people to consider the possibility that AI could accelerate mathematical discoveries. At the same time, he cautioned against rushing to transfer funds to new wallets and drew attention not only to ECDSA, but also to other cryptographic approaches, including ML-DSA and fully homomorphic encryption (FHE).
In Hoskinson’s view, Buterin does not give sufficient consideration to the results of decades of research into lattice-based cryptography. He cited the LLL and BKZ algorithms, as well as sieving methods, which researchers have taken into account when assessing the security of such schemes and selecting security parameters.
Hoskinson emphasized that ML-KEM and ML-DSA were developed with known attacks in mind. He also noted that any potential new attack should undergo the standard review process: researchers must assess its computational cost and determine whether the parameters of the cryptographic schemes need to be changed.
He also mentioned research into quantum attacks on certain types of lattices. According to him, these findings have influenced the assessment of some schemes, but they do not prove that ML-KEM or ML-DSA can be broken using similar methods.
Hoskinson also questioned the argument that hash-based cryptography is automatically more secure because it lacks certain mathematical structures. He pointed to the breaks of MD5 and SHA-1 and noted that the hash functions used in modern proof systems also rely on their own cryptographic assumptions and carry potential risks.
Hoskinson warned of consequences for post-quantum security
According to the Cardano founder, calls to heighten concerns about lattice-based cryptography excessively could have practical consequences. In particular, he believes this could make it harder to deploy ML-KEM, a key encapsulation mechanism used in post-quantum security.
Hoskinson linked this to the risk of “harvest now, decrypt later” attacks, in which malicious actors collect encrypted traffic in the hope of being able to decrypt it in the future. He noted that delays in deploying post-quantum mechanisms could leave more communications protected by traditional cryptography.
At the same time, Hoskinson did not deny that hash-based signatures could be useful in relevant scenarios. His criticism was primarily aimed at the idea of abandoning lattice-based cryptography without a specific attack and a quantitative assessment of its effectiveness.
In conclusion, he said that assessments of cryptographic risks should be based on specific attack algorithms, cost estimates, and well-founded choices of security parameters—not on assumptions that artificial intelligence could accelerate mathematical discoveries over the next two years.
Recall that the Cardano founder previously estimated the risk of a quantum threat to the crypto industry at over 50%.
