In July 2022, two researchers at KU Leuven, Wouter Castryck and Thomas Decru, published a paper that broke SIKE (Supersingular Isogeny Key Encapsulation), one of the four NIST Round 4 KEM finalists. SIKE was supposed to be one of the most promising compact post-quantum schemes: 200-byte ciphertexts, similarly small public keys, no decoding failures. Castryck and Decru's attack ran on a single laptop and recovered the SIKE-Level-1 private key in about an hour. Within weeks, follow-up papers extended the break to all SIKE parameter sets. NIST removed SIKE from the competition.
The break did not kill isogeny-based cryptography. It killed a specific scheme (SIDH/SIKE) by exploiting its specific structure (auxiliary torsion points). Other isogeny constructions, with different structures, survived. This article explains what isogeny crypto is, what went wrong with SIKE, and where the field stands now in 2026.
What Isogenies Are
Elliptic curve cryptography (ECC) uses elliptic curves over finite fields. The hard problem in classical ECC is the discrete logarithm: given P and Q on a curve, find n such that Q = nP. Quantum computers solve this efficiently using Shor's algorithm.
Isogeny-based cryptography uses elliptic curves too, but with a different hard problem. Instead of points on a curve, isogeny crypto uses maps between curves. An isogeny is a non-trivial homomorphism from one elliptic curve to another. A key fact: there are exponentially many isogenies between two curves, and finding a specific isogeny is conjectured to be hard, even for quantum computers.
The hardness of isogeny problems comes from a different mathematical structure than discrete logarithm. Quantum computers do not have a direct algorithm to solve isogeny problems. The best known quantum algorithm uses Grover-style search and gives only a square-root speedup, which means doubling the security parameter restores classical-level security.
For background on the broader picture of post-quantum families, see What Is Post-Quantum Cryptography?.
What Went Wrong With SIKE
SIDH (Supersingular Isogeny Diffie-Hellman) was proposed in 2011 by De Feo, Jao, and Plut. SIKE was the KEM built from SIDH. The protocol used pairs of curves connected by isogenies, with a key element being "auxiliary torsion points" that helped the parties compose isogenies efficiently.
The auxiliary torsion points were the weakness. Castryck and Decru showed that knowing the action of the secret isogeny on auxiliary points, plus algebraic structure from the isogeny graph, allowed reconstruction of the isogeny itself. Their key insight came from "glue and split" techniques in genus-2 curve theory, applied to the supersingular isogeny graph.
The attack:
- Used the auxiliary torsion points to set up a system of equations relating the unknown secret isogeny to known curve information.
- Applied glue-and-split to find the isogeny in polynomial time on a classical computer.
- Recovered the secret key in around one hour for SIKE-Level-1.
Subsequent papers extended the attack to all SIKE parameter sets, including the ones meant for Level 5 security. Within weeks of the original break, SIKE was demonstrably insecure.
The general lesson: structured auxiliary information (the torsion points) provided the algebraic leverage attackers used. Schemes that do not expose torsion points are not vulnerable to the same attack.
What Survived: SQIsign
The most prominent isogeny scheme to survive is SQIsign (Short Quaternion and Isogeny Signature), proposed by De Feo, Kohel, Leroux, Petit, and Wesolowski in 2020. SQIsign is a signature scheme, not a KEM. Its security is based on a different problem (the supersingular endomorphism ring problem), and it does not expose auxiliary torsion points.
SQIsign features:
- Compact signatures: Around 200 bytes, the smallest of any post-quantum signature.
- Compact public keys: Around 100 bytes.
- Slow signing: Several seconds per signature on commodity hardware. This is the main practical limitation.
- Reasonable verification: Around 100 milliseconds.
- Different hard problem: Endomorphism ring problem, not the SIDH/SIKE problem. The Castryck-Decru attack does not apply.
SQIsign was submitted to the NIST signature on-ramp call in 2023 and advanced to Round 2 in 2024. Cryptanalytic confidence has held since the submission. See NIST Signature On-Ramp for more on the broader on-ramp.
CSIDH: Commutative SIDH
CSIDH (Commutative SIDH, pronounced "seaside") was proposed in 2018 as a CSIDH-based key exchange. Like SIDH, it uses isogenies, but on a commutative class group rather than the SIDH structure. CSIDH does not expose auxiliary torsion points and was not affected by the Castryck-Decru break.
However, CSIDH has its own challenges:
- Slow: Original CSIDH-512 takes about half a second per key exchange. Optimisations (CSURF, dCTIDH) bring it down to tens of milliseconds.
- Subexponential quantum attack: Kuperberg's algorithm gives a sub-exponential quantum speedup against CSIDH. To resist quantum adversaries, CSIDH parameters need larger fields than initially proposed. Specifically, CSIDH-512 is now considered insufficient against quantum attackers, and CSIDH-2048 or larger is needed.
- Patchy provable security: CSIDH's quantum security relies on assumptions that are less studied than lattice or code-based assumptions.
CSIDH has not been submitted to a NIST standardisation process and is mostly a research scheme. A few research libraries implement it (libsidh, isogeny-crypto from KU Leuven).
SCALLOP and Other Variants
After SIDH/SIKE was broken, several research groups proposed new isogeny-based KEMs that avoid the SIDH structure:
SCALLOP (Sailing the Class Group): Uses the class group action like CSIDH but with optimisations for security against Kuperberg's algorithm. Better performance than CSIDH at equivalent security.
SiGamal: A KEM based on the supersingular endomorphism ring problem (similar to SQIsign).
FESTA: A KEM that uses isogenies with two-torsion structure but in a way that is not vulnerable to the Castryck-Decru attack.
M-SIDH and MD-SIDH: Modifications to SIDH that mask the auxiliary torsion points to defeat the Castryck-Decru attack. These have been published but are still being studied for cryptanalytic robustness.
None of these is on a NIST standardisation track as of early 2026. They are research schemes that may eventually be submitted to a future NIST KEM diversification call (if one materialises).
Why Isogeny Crypto Matters
Despite the SIKE break, isogeny cryptography remains valuable for several reasons:
Mathematical diversity: The hardness assumption is fundamentally different from lattices, codes, or hashes. If a future attack on lattices materialises, isogeny schemes provide a different family for fallback.
Compact parameters: Isogeny schemes typically have the smallest public keys and signatures of any post-quantum family. SQIsign signatures are 10x smaller than ML-DSA signatures. For applications where bandwidth is the bottleneck (IoT, certificate transparency), this is significant.
Long-term research promise: The mathematical machinery (supersingular isogeny graphs, quaternion algebras) is rich and supports many constructions beyond just KEM/signature, including identity-based crypto, ring signatures, and more exotic primitives.
For more on lattice-based comparison, see Lattice-Based Cryptography Explained.
SQIsign Performance Reality
For users curious about SQIsign's practical numbers, the current benchmarks are roughly:
- Public key: 64 bytes (SQIsign-1) to 130 bytes (SQIsign-5).
- Signature: 177 bytes (SQIsign-1) to 380 bytes (SQIsign-5).
- Signing time: 2 to 10 seconds on commodity x86.
- Verification time: 50 to 200 milliseconds.
The signing time is the deal-breaker for most applications. ML-DSA signs in microseconds. SQIsign signs in seconds. For applications that produce signatures rarely (firmware signing, root CA signing, code release signing), the time is acceptable. For applications that produce signatures frequently (TLS handshake, V2V, blockchain transactions), SQIsign is too slow.
Active research is reducing signing time. SQIsignHD (a 2023 variant) brings signing to about 1 second. SQIsign2D (under development) targets sub-second signing. None has reached production maturity.
The trade-off SQIsign offers is: compactness for slowness. If you can tolerate seconds-per-signature, you get the smallest post-quantum signature and the most compact public key. For niche use cases (long-term archive signing, smart-card-friendly signatures), this is attractive.
Why Diversity Matters for Production
The strategic argument for keeping isogeny research alive: post-quantum cryptography rests on a small number of mathematical hardness assumptions. If lattices are weakened by a future breakthrough, the world needs a fallback. If codes are weakened, similarly. Isogenies provide a fundamentally different family.
The SIKE break demonstrates that isogeny crypto is not yet as well-understood as lattice or code-based crypto. But it also shows that targeted attacks against specific structures do not necessarily generalise. SQIsign and CSIDH-family schemes use different structures and remain plausible.
For organisations planning long-term cryptographic strategy, isogeny crypto is a research bet, not a deployment recommendation. The recommendation is: deploy NIST-standardised schemes today, watch the isogeny literature, and consider isogeny schemes once one is standardised (likely SQIsign in 2027 or 2028 if Round 2 of the on-ramp goes well).
For more on diversity strategy, see NIST PQC Standards Timeline.
What QNSQY Provides
QNSQY ships ML-KEM (lattice) and HQC (code-based) for KEM, and ML-DSA, FN-DSA, SLH-DSA for signatures. None is isogeny-based. Isogeny schemes are not on the NIST FIPS track and are research-grade as of 2026.
If SQIsign or another isogeny scheme is standardised in the future, QNSQY's hybrid envelope format is extensible to add it. The Business tier would be the natural home for an isogeny option, providing maximum mathematical diversity to users who want it. See Hybrid Encryption for the envelope design.
For users tracking post-quantum diversity, isogeny crypto sits in a different category than lattice or code-based crypto. It is mathematically further from classical primitives, has different attack surfaces, and may eventually offer the smallest signatures of any post-quantum family. The 2022 SIKE break was a setback, not a death sentence, and SQIsign's progress through Round 2 of the NIST signature on-ramp will be a key milestone to watch in 2026 and 2027.
Frequently Asked Questions
Is isogeny cryptography dead after SIKE was broken?
No. SIKE used a specific structure (auxiliary torsion points) that turned out to be exploitable. Other isogeny schemes (SQIsign, CSIDH, SCALLOP) use different structures and were not affected. Isogeny crypto research continues actively.
What is SQIsign and is it standardised?
SQIsign is a post-quantum signature scheme based on the supersingular endomorphism ring problem. It produces very small signatures (around 200 bytes) but signing is slow (seconds). It is not standardised as of 2026 but is in NIST's signature on-ramp Round 2 evaluation.
Could the SIKE attack be extended to other isogeny schemes?
The Castryck-Decru attack specifically exploits auxiliary torsion points in the SIDH structure. Schemes that do not expose those points (SQIsign, CSIDH, SCALLOP, FESTA) are not directly vulnerable. New attacks could emerge but would likely be different in structure.
Why is CSIDH slow?
CSIDH's underlying isogeny computations involve walking through many small isogeny steps in a commutative class group. Each step is fast, but the walk is long. Optimisations like CSURF and dCTIDH have reduced timing significantly, but it remains slower than lattice or hash-based schemes.
Should I use isogeny cryptography in production today?
For most production use cases, no. Isogeny schemes are research-grade and not standardised. Use NIST-standardised schemes (ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC) for production deployments. Isogeny crypto is interesting to watch but not yet appropriate for compliance-bound systems.
Why was the SIKE break possible after years of analysis?
The Castryck-Decru attack used techniques from genus-2 algebraic geometry that had not been applied to the supersingular isogeny graph before 2022. The "glue and split" method bridged two areas of mathematics in a way that revealed a polynomial-time algorithm for the underlying SIDH problem when auxiliary torsion points are exposed. This pattern is common in cryptanalysis: a scheme survives many years of analysis using one set of techniques, then a researcher applies a fresh perspective and finds a break. It is part of why post-quantum standardisation includes multiple algorithm families.
What use cases benefit most from isogeny cryptography?
Bandwidth-constrained applications. SQIsign signatures are about 200 bytes, an order of magnitude smaller than ML-DSA-65's 3.3 KB. For embedded systems, mesh networks, satellite communications, and any context where every byte matters, isogeny signatures are attractive. The trade-off is signing speed (seconds for SQIsign), which limits use to scenarios where signatures are produced occasionally rather than continuously.
Sources
- Castryck, W., Decru, T. "An Efficient Key Recovery Attack on SIDH." EUROCRYPT 2023. https://eprint.iacr.org/2022/975
- De Feo, L., Kohel, D., Leroux, A., Petit, C., Wesolowski, B. "SQISign: Compact Post-Quantum Signatures from Quaternions and Isogenies." ASIACRYPT 2020. https://eprint.iacr.org/2020/1240
- Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J. "CSIDH: An Efficient Post-Quantum Commutative Group Action." ASIACRYPT 2018. https://eprint.iacr.org/2018/383
- De Feo, L., Jao, D., Plut, J. "Towards Quantum-Resistant Cryptosystems from Supersingular Elliptic Curve Isogenies." Journal of Mathematical Cryptology, 2014. https://eprint.iacr.org/2011/506
- Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B. "A Direct Key Recovery Attack on SIDH." EUROCRYPT 2023. https://eprint.iacr.org/2023/640
- Page, A., Robert, D., et al. "Introducing Clapoti(s): Evaluating the Isogeny Class Group Action in Polynomial Time." 2023. https://eprint.iacr.org/2023/1766
- Robert, D. "Breaking SIDH in polynomial time." EUROCRYPT 2023. https://eprint.iacr.org/2022/1038
- NIST. "Post-Quantum Cryptography Project." https://csrc.nist.gov/projects/post-quantum-cryptography
Related Articles
- What Is Post-Quantum Cryptography?
- NIST Signature On-Ramp
- NIST PQC Standards Timeline
- Lattice-Based Cryptography Explained
- HQC Explained
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.