On July 30, 2022, Wouter Castryck and Thomas Decru of KU Leuven published a paper called "An efficient key recovery attack on SIDH". By breakfast on August 1, every cryptographer who watched the IACR ePrint feed knew that the Supersingular Isogeny Key Encapsulation scheme, a Round 3 alternate advanced to NIST's Round 4, had just collapsed. The reference implementation took about an hour on a single laptop to recover the SIKEp434 private key. Within a week, Damien Robert and others had extended the attack to break SIKEp503, p610, and p751 on similar timescales.
This was the cleanest cryptographic break of the modern era. No backdoor. No side channel. Just a piece of mathematics that should have been spotted years earlier, finally walking onto the stage and ending the scheme. SIKE had been a NIST finalist for almost five years, had been studied by hundreds of researchers, and was about to be standardised. Then it was gone.
This article walks through what SIKE was trying to do, how Castryck and Decru broke it, and what the lesson is for everyone designing post-quantum cryptography in the aftermath.
The Maze With Hidden Shortcuts
Imagine a maze with millions of intersections. At each intersection you can turn left or right. Two friends each pick a long path through the maze and both end up at the same exit. They trade some clues with each other (turning information at certain checkpoints), and they need to compute a shared secret based on the combined paths. An adversary watching the clues should not be able to figure out either friend's path.
That was the SIDH (Supersingular Isogeny Diffie-Hellman) protocol, proposed by Luca De Feo and David Jao in 2011. The "maze" was the graph of supersingular elliptic curves, and the "turning" was an isogeny, a structure-preserving map between curves. Each isogeny step transforms one elliptic curve into another. After many steps, you arrive at a curve whose properties can be combined with your peer's curve to compute a shared secret.
The great selling point was key size. SIKE's compressed public keys were just 197 bytes for SIKEp434, far smaller than ML-KEM's 1,184 bytes or NTRU's 699 bytes. For tight bandwidth budgets, satellite links, embedded radios, and protocols where every byte matters, SIKE was the dream candidate.
SIDH and SIKE: The Technical Setup
SIDH was published in 2011. SIKE (the IND-CCA2-secure KEM wrapper around SIDH) was submitted to NIST's post-quantum competition in November 2017. The submission team included Reza Azarderakhsh, Matthew Campagna, Craig Costello, Luca De Feo, Basil Hess, Amir Jalali, David Jao, Brian Koziel, Brian LaMacchia, Patrick Longa, Michael Naehrig, Joost Renes, Vladimir Soukharev, David Urbanik, and others. It was a large, competent team with deep number-theory expertise.
By Round 3 (July 2020), SIKE was the only isogeny-based scheme still standing. NIST advanced it to Round 4 (July 2022) as an alternate KEM, alongside Classic McEliece, BIKE, and HQC. Standardisation seemed within reach, perhaps by 2024 or 2025.
The Auxiliary Points
A subtle feature of SIDH made the attack possible: each party published not just their final curve but also two auxiliary points on it. The auxiliary points were necessary for the protocol to work, because they let the other party "translate" their secret kernel into the partner's curve. Designers had analysed these auxiliary points for over a decade and concluded they leaked no usable structure.
That conclusion turned out to be wrong.
The Castryck-Decru Attack, Step by Step
The 2022 paper showed how the auxiliary points, combined with a new technique by Ernst Kani going back to his 1997 paper on isogenies between abelian surfaces, could be used to recover the secret isogeny kernel directly. The attack does not solve a hard mathematical problem. It exploits a structural weakness that had been hiding in plain sight.
The high-level flow:
- Take the public auxiliary points and the published codomain curve.
- Use Kani's theorem to construct an isogeny between abelian surfaces (a 2-dimensional analogue of an elliptic curve).
- Compute that 2-dimensional isogeny step by step. Each step is feasible because the dimensions are small and the surfaces have known structure.
- Read off the original secret kernel from the resulting computation.
The reference attack ran in about 62 minutes on a single core for SIKEp434 (NIST Category 1, ~AES-128 security). Stronger SIKE parameter sets fell within hours. The attack scales polynomially in the parameter size, which means even SIKEp751 (Category 5, ~AES-256) fell to the reference attack in under a day of single-core compute, and optimized reimplementations cut the attack times further still.
Why the Community Missed This
Cryptographic community estimates of SIDH security had focused on three classes of attack: brute-force isogeny enumeration, generic algorithms like Pollard rho, and structural attacks targeting torsion subgroups. None of these had panned out. Kani's theorem and its application to isogeny graphs had not been on most cryptographers' radar.
Castryck and Decru come from algebraic geometry. They saw a tool that the isogeny-cryptography community had not been thinking about, and they applied it cleanly. Within weeks, several teams reproduced and extended the attack. By August 22, 2022, the SIKE team officially withdrew from the NIST competition.
NIST's Response
NIST's Round 4 evaluation criteria included a clause about ongoing cryptanalysis. When a finalist was broken, the schedule would adjust accordingly. SIKE's removal in August 2022 left the Round 4 KEM alternates with three remaining candidates: Classic McEliece, BIKE, and HQC.
In March 2025, NIST announced that HQC was selected as the Round 4 winner for non-lattice KEM diversification. Classic McEliece and BIKE remained on the table for future standardisation discussions but did not get a FIPS slot at that time.
The lesson NIST drew was explicit: cryptographic diversity matters. If ML-KEM ever falls to a lattice attack, HQC (code-based) is the conservative non-lattice fallback. Without that diversification, a single math result could end NIST's whole post-quantum suite.
What Survives From Isogeny Cryptography
SIKE is dead. SIDH, the underlying protocol, is also dead. But the broader field of isogeny cryptography lives on with several surviving designs:
- CSIDH (Castryck-Lange-Martindale-Panny-Renes, 2018): A commutative variant of supersingular isogeny Diffie-Hellman. CSIDH does not publish auxiliary points and does not use Kani's surface trick. The Castryck-Decru attack does not apply. CSIDH remains a candidate for non-interactive key exchange, although its performance is significantly worse than SIDH was.
- SQIsign (De Feo, Kohel, Leroux, Petit, Wesolowski, 2020): An isogeny-based digital signature with very small signatures (about 200 bytes). NIST's "On-Ramp" call for additional signatures in 2023 included SQIsign as a Round 1 candidate. It is too slow for high-volume use but compelling for tight-bandwidth scenarios.
- FESTA (Basso-Maino-Pope, 2023): A trapdoor-isogeny KEM that learned from SIKE's mistakes by avoiding the auxiliary-point structure that Castryck and Decru exploited.
For more on what came before and after, see SIDH History.
The Status of Isogeny Cryptography Today
The field is bruised but not dead. Researchers are now extra careful about what auxiliary information leaks during a protocol. The SQIsign team has explicitly designed around the lessons of SIKE's break. NIST's signature on-ramp keeps isogeny-based candidates in the running. But for KEMs in 2026, the production-grade options are ML-KEM (lattice) and HQC (code), not anything isogeny-based.
The Lessons for Post-Quantum Cryptography
Three takeaways from the SIKE break that shape every post-quantum decision today:
- Diversity is mandatory. NIST kept Classic McEliece, BIKE, and HQC alive as non-lattice alternates precisely because of attacks like the SIKE break. If you only have lattice schemes, a single attack on lattices ends your entire portfolio.
- Math you have not heard of can break your scheme. Kani's theorem was 25 years old when Castryck and Decru applied it to SIDH. Cryptographic schemes survive only as long as the cryptanalysis community has fully explored every relevant tool. SIKE survived 11 years; that was not enough.
- Conservative is better than clever. SIKE's small key sizes were a striking advantage. Hash-based SLH-DSA and code-based McEliece are clunky but they sit on assumptions decades older than isogenies. If you need bet-the-data security, clunky and old usually beats elegant and new.
SIKE in QNSQY's History
QNSQY never shipped SIKE. The original architecture decisions in 2023 were made after the Castryck-Decru attack, so SIKE was never on the table. QNSQY's KEM portfolio at launch was ML-KEM (lattice, FIPS 203) plus an optional HQC (code, NIST Round 4 winner) for Business tier customers who wanted non-lattice diversity. See HQC Explained.
If we had launched in 2021 with SIKE in the suite, we would have had to do a forced re-encryption of every file to upgrade users away from a broken algorithm. The harvest-now-decrypt-later threat model means files encrypted under a broken algorithm in 2021 are forever exposed once an adversary captured them. SIKE's collapse is the most direct argument for why algorithmic diversity is not a luxury.
Cloudflare's SIKE Retirement
The most public production exposure to SIKE was the Cloudflare-Google CECPQ2b experiment in 2019, a hybrid X25519+SIKE TLS deployment run for measurement purposes alongside CECPQ2 (X25519 + NTRU-HRSS). Those experiments had concluded before the attack, and any remaining experimental SIKE options were retired immediately after it. The retirement was clean because the deployments had been explicitly experimental, with no production traffic relying on SIKE for security.
Other organisations that had been considering SIKE (some experimental TLS extensions, some academic protocol drafts) similarly pulled the scheme. Within weeks of the attack, the only production-relevant SIKE traces were in research code repositories, not active deployments. The lesson for early adopters: keep your post-quantum experiments isolated from production until standardisation completes, so that attacks on candidate schemes do not become operational events.
Frequently Asked Questions
Did the SIKE break affect any deployed systems?
In production, very few. SIKE was a Round 4 alternate, not a finalised standard. Cloudflare ran an experimental hybrid SIKE/X25519 deployment in 2022 that was retired immediately after the attack was published. Most production post-quantum deployments waited for ML-KEM standardisation. The SIKE break was a research disaster but a small operational footprint.
Could the same kind of attack break ML-KEM?
The Castryck-Decru attack is specific to SIDH's auxiliary-point structure. It does not apply to lattice schemes. That said, no one promises lattices are safe forever. NIST's portfolio approach (ML-KEM + HQC) exists precisely so that a hypothetical future lattice break does not leave the world without a working KEM. See Why RSA-2048 Will Break for the parallel story on the classical side.
Is isogeny cryptography dead now?
SIDH and SIKE are dead. CSIDH and SQIsign survive because they do not have the auxiliary-point structure that the attack exploited. They are not yet production-grade KEMs at NIST scale, but they remain active research areas. Isogeny cryptography is bruised, not extinct.
How fast was the actual attack?
About 62 minutes for SIKEp434 (Category 1) on a single core of an Intel Xeon E5-2630v2, and roughly a day of single-core compute for SIKEp751 (Category 5) with the reference code; optimized reimplementations were faster still. For comparison, breaking ML-KEM-512 by exhaustive search would take more than the lifetime of the universe.
Sources
- Castryck, W., Decru, T. "An efficient key recovery attack on SIDH." IACR ePrint 2022/975. https://eprint.iacr.org/2022/975
- Robert, D. "Breaking SIDH in polynomial time." IACR ePrint 2022/1038. https://eprint.iacr.org/2022/1038
- NIST. "PQC Standardization Process: Announcing Four Candidates to be Standardized, Plus Fourth Round Candidates." July 5, 2022. https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4
- NIST. "Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process." NIST IR 8528, March 2025. https://csrc.nist.gov/pubs/ir/8528/final
- Jao, D., De Feo, L. "Towards Quantum-Resistant Cryptosystems from Supersingular Elliptic Curve Isogenies." PQCrypto 2011. https://eprint.iacr.org/2011/506
- Maino, L., Martindale, C. "An attack on SIDH with arbitrary starting curve." IACR ePrint 2022/1026. https://eprint.iacr.org/2022/1026
Related Articles
- HQC Explained
- SIDH History
- NIST FIPS Guide for Post-Quantum Standards
- What Is Post-Quantum Cryptography?
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.