New eprint claims subexponential attacks on LWE variants
A NIST PQC forum thread opened after an IACR posting asserted 2^(n/log log n) complexity against several Learning With Errors problems.
A newly posted IACR ePrint paper claims subexponential-time attacks on various Learning With Errors (LWE) problems, with stated complexity on the order of 2^(n/log log n).
LWE underpins lattice-based cryptography, including multiple schemes NIST has standardized for post-quantum key encapsulation and signatures. A genuine advance of this form would affect how those constructions are parameterized and how long their security assumptions are expected to hold.
Jacob Alperin-Sheriff brought IACR ePrint 2026/2386 to the NIST post-quantum cryptography forum, noting he had not yet read the paper and calling for a substantive, respectful technical discussion. Independent assessment of the claims is not reflected in the initial notice.