China’s Institute for Commercial Cryptography Standard copied NIST’s model and is running an open contest for post-quantum crypto and hash functions: the Next-generation Commercial Cryptographic Algorithms Program (NGCC).
The call for submissions was a poor copycat of NIST’s documents, and the website looks straight from 1999:
On Sept 20, the NGCC announced the candidates hash functions and PQC:
35 hash functions
34 signature schemes
1 code-based
4 hash-
3 isogeny-
11 lattice-
9 MPC-in-the-head
5 multivariate
1 “alternating trilinear form equivalence”-based (?)
41 key encapsulation schemes
15 code-based
1 isogeny-
25 lattice-
9 key exchange schemes
1 code-based
1 isogeny-
7 lattice-
Or 119 submissions in total.
I remember how fun it was as a PhD student to break the low-hanging-fruit submissions to SHA3 back in 2008. But today’s junior cryptographers won’t have this chance because LLMs find in minutes the attacks it takes a human hours or days to find.
The agents of Markku Saarinen—brilliant cryptographer—went on a rampage: at the time of writing, they found
164 active findings across 86 reports: 76 implementation, 59 design, 29 side-channel; 2 withdrawn records.
including 54 critical-rated attacks/bugs (some submissions have multiple critical issues.) Not all findings have already been confirmed to be valid, but I found a couple of issues myself independently on hash functions and could easily verify most of them.
Of the 119 submissions, only 33 are tagged “No report.”
It’s just been five days. Will China have any unbroken submission left in a month?

