Mental model
In M4 you saw that ML-KEM, ML-DSA, SLH-DSA and FN-DSA (Falcon) are candidates still standing, standardized or on the way to standardization. This lesson covers two losing candidates from the same NIST competition, SIKE (a KEM) and Rainbow (a signature scheme), and why they lost. These cases matter at a different point from HAWK (next lesson): HAWK was withdrawn by its own team, while SIKE and Rainbow were eliminated within NIST’s own process, both because of real, serious mathematical attacks.
SIKE: an isogeny-based KEM, collapsed in 25 days
SIKE was a key encapsulation mechanism based on isogenies between elliptic curves (roughly: a special mathematical map taking one elliptic curve to another). On 5 July 2022SOURCED, when NIST selected ML-KEM/ML-DSA/FN-DSA/SLH-DSA for standardization, it moved SIKE (together with BIKE, Classic McEliece and HQC) into a Round 4 for further study, at CANDIDATE status, not yet selected.
Only 25 days later, on 30 July 2022SOURCED, Wouter Castryck and Thomas Decru published an attack: using the auxiliary torsion point information SIKE exchanges during the protocol (torsion points are special points of a particular order on an elliptic curve), and based on a technique called Kani’s “reducibility criterion”, the attack broke the SIKEp434 (security level 1) private key in about ten minutesSOURCED on a single core. This is a classical attack, meaning it needs no quantum computer; an ordinary desktop is enough. In March 2025, NIST IR 8545 formally put it on record: SIKE is an insecure KEM, and it has been eliminated from the NIST PQC project.SOURCED. Today SIKE has WITHDRAWN2025-03-01 status.
Rainbow: a signature finalist, broken over a weekend
Rainbow was a signature scheme based on systems of multivariate polynomial equations (multivariate cryptography), and unlike SIKE it was already one of NIST’s Round 3 signature finalists (alongside ML-DSA and FN-DSA), one of three candidates evaluated without even needing a Round 4. With an attack published in February 2022 (an improved version of the “rectangular MinRank” technique, a family of algebraic attacks that try to find a cryptographic structure’s secret key through rank constraints, built on the earlier “band separation” attack), Ward Beullens broke the private key of Rainbow’s SL1 (security level 1) parameters in 53 hoursSOURCED on a standard laptop; hence the paper’s title, “Breaking Rainbow Takes a Weekend on a Laptop.”
In July 2022, NIST IR 8413, in the same report that selected Kyber/Dilithium/Falcon/SPHINCS+, wrote of Rainbow: NIST decided not to advance Rainbow.SOURCED. Unlike SIKE, Rainbow was never moved to a “Round 4”; it was eliminated directly in Round 3. Today Rainbow has WITHDRAWN2022-07-01 status.
The same pattern, two different kinds of math: why this is a success story
The differences between the two cases (SIKE a KEM, Rainbow a signature; SIKE isogeny-based, Rainbow multivariate; SIKE eliminated in Round 4, Rainbow in Round 3) matter, but the common point matters more: both attacks were published as public academic papers, on ordinary hardware, before the schemes became standards. That is evidence NIST’s multi-candidate, multi-year evaluation process did exactly what it should: eliminate weak mathematical foundations before they reach production. The lattice problems ML-KEM rests on (the LWE you saw in M2) and the structure behind ML-DSA are a different mathematical family from isogenies and multivariate equations; SIKE and Rainbow being broken does not mean ML-KEM/ML-DSA will be broken too; on the contrary, it shows that different mathematical families are at different levels of maturity.
Update, October 2026: the same pattern, at speed
The pattern repeated in September 2026, outside the NIST process. China’s Institute of Commercial Cryptography Standards published 119 first-round candidates for its next-generation commercial cryptography program on 20 September; within three days public reviewers had logged findings against dozens of them, including practical breaks of several designs, according to a public findings index and a secondary summary. Open review breaks young designs quickly, which is exactly why production should rest only on schemes that have survived it. Details on the news desk.