Get the latest tech news
Understanding lattice risks: Many differences between marketing and reality
I have a short new page giving general context for the following and links to further information, so I'll just jump straight into the specific topic here. Here's a paragraph that appeared on 29 June 2026 as supposed justification for using solo ML-KEM rather than ECC+ML-KEM: "I do not believe the risk of ML-KEM (and ML-DSA) to be severe: there is no known cryptanalysis currently exploiting rank >=2 module structure at these parameters that performs better than generic lattice reduction.
None
Or read this on Hacker News

