M14 / What breaks

SIKE and Rainbow: two real collapses, two versions of the same lesson

FoundationsPractitionerAdvisor

After this lesson you can

  • Explain why and how SIKE (an isogeny-based KEM) and Rainbow (a multivariate signature) were removed from the NIST process, with their real mathematical weaknesses
  • Draw from both cases the lesson that 'being broken before becoming a standard is actually evidence the system works'

Before thisM4: Signatures

Mental model

In M4 you saw that ML-KEM, ML-DSA, SLH-DSA and FN-DSA (Falcon) are candidates still standing, standardized or on the way to standardization. This lesson covers two losing candidates from the same NIST competition, SIKE (a KEM) and Rainbow (a signature scheme), and why they lost. These cases matter at a different point from HAWK (next lesson): HAWK was withdrawn by its own team, while SIKE and Rainbow were eliminated within NIST’s own process, both because of real, serious mathematical attacks.

SIKE: an isogeny-based KEM, collapsed in 25 days

SIKE was a key encapsulation mechanism based on isogenies between elliptic curves (roughly: a special mathematical map taking one elliptic curve to another). On 5 July 2022SOURCED, when NIST selected ML-KEM/ML-DSA/FN-DSA/SLH-DSA for standardization, it moved SIKE (together with BIKE, Classic McEliece and HQC) into a Round 4 for further study, at CANDIDATE status, not yet selected.

Only 25 days later, on 30 July 2022SOURCED, Wouter Castryck and Thomas Decru published an attack: using the auxiliary torsion point information SIKE exchanges during the protocol (torsion points are special points of a particular order on an elliptic curve), and based on a technique called Kani’s “reducibility criterion”, the attack broke the SIKEp434 (security level 1) private key in about ten minutesSOURCED on a single core. This is a classical attack, meaning it needs no quantum computer; an ordinary desktop is enough. In March 2025, NIST IR 8545 formally put it on record: SIKE is an insecure KEM, and it has been eliminated from the NIST PQC project.SOURCED. Today SIKE has WITHDRAWN2025-03-01 status.

Rainbow: a signature finalist, broken over a weekend

Rainbow was a signature scheme based on systems of multivariate polynomial equations (multivariate cryptography), and unlike SIKE it was already one of NIST’s Round 3 signature finalists (alongside ML-DSA and FN-DSA), one of three candidates evaluated without even needing a Round 4. With an attack published in February 2022 (an improved version of the “rectangular MinRank” technique, a family of algebraic attacks that try to find a cryptographic structure’s secret key through rank constraints, built on the earlier “band separation” attack), Ward Beullens broke the private key of Rainbow’s SL1 (security level 1) parameters in 53 hoursSOURCED on a standard laptop; hence the paper’s title, “Breaking Rainbow Takes a Weekend on a Laptop.”

In July 2022, NIST IR 8413, in the same report that selected Kyber/Dilithium/Falcon/SPHINCS+, wrote of Rainbow: NIST decided not to advance Rainbow.SOURCED. Unlike SIKE, Rainbow was never moved to a “Round 4”; it was eliminated directly in Round 3. Today Rainbow has WITHDRAWN2022-07-01 status.

The same pattern, two different kinds of math: why this is a success story

The differences between the two cases (SIKE a KEM, Rainbow a signature; SIKE isogeny-based, Rainbow multivariate; SIKE eliminated in Round 4, Rainbow in Round 3) matter, but the common point matters more: both attacks were published as public academic papers, on ordinary hardware, before the schemes became standards. That is evidence NIST’s multi-candidate, multi-year evaluation process did exactly what it should: eliminate weak mathematical foundations before they reach production. The lattice problems ML-KEM rests on (the LWE you saw in M2) and the structure behind ML-DSA are a different mathematical family from isogenies and multivariate equations; SIKE and Rainbow being broken does not mean ML-KEM/ML-DSA will be broken too; on the contrary, it shows that different mathematical families are at different levels of maturity.

Update, October 2026: the same pattern, at speed

The pattern repeated in September 2026, outside the NIST process. China’s Institute of Commercial Cryptography Standards published 119 first-round candidates for its next-generation commercial cryptography program on 20 September; within three days public reviewers had logged findings against dozens of them, including practical breaks of several designs, according to a public findings index and a secondary summary. Open review breaks young designs quickly, which is exactly why production should rest only on schemes that have survived it. Details on the news desk.

Numbers to know

  • SIKE: moved to Round 4 (further study) on 5 July 2022; 25 days later (30 July 2022) the Castryck-Decru attack was published, breaking SIKEp434 in ~10 minutes on a single core; in March 2025 NIST IR 8545 formally declared SIKE 'eliminated from the NIST PQC project'
  • Rainbow: a Round 3 signature finalist; Beullens's attack broke the SL1 private key in 53 hours on average ('a weekend') on a standard laptop; in July 2022 NIST IR 8413 did 'not select' Rainbow in the SAME report that selected Kyber/Dilithium/Falcon/SPHINCS+
  • Both attacks are classical (non-quantum) mathematical attacks; they need no quantum computer and run on an ordinary laptop

Lab: Compare the timelines of the two cases yourself

[not run] This is a source comparison exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Read the abstracts of eprint.iacr.org/2022/975 and eprint.iacr.org/2022/214 side by side; in each, find the sentence 'the attack ran in X hours/minutes on a standard computer'
Recorded output
Two different algorithm families (isogeny versus multivariate), two different authors, the same year (2022), the same theme: no special hardware, an ordinary laptop or desktop is enough

At the table

How to say this in a bank meeting.

To an executive
Two PQC candidates were eliminated, before becoming standards, because of real mathematical weaknesses. That is not a failure but evidence the NIST process works exactly as designed: because there was an evaluation period, they were broken before reaching production.
To an architect
Neither SIKE nor Rainbow was ever deployed anywhere in production as a standard; the risk of finding these two algorithms in any of your bank's systems is close to zero. What matters is the pattern these cases carry into the rest of M14 (HAWK, Simon 2026): a candidate resting on a new mathematical structure can stay breakable until it becomes a standard.
Objection
“"If PQC algorithms keep getting broken, isn't that a reason not to trust PQC at all?"”
Answer
The opposite: SIKE and Rainbow being broken is indirect evidence of the trustworthiness of ML-KEM and ML-DSA (the most studied candidates, still standing, which you saw in M2-M4). Some members of a candidate pool being broken shows whether the remaining members have been studied less or more: the NIST process exists exactly to do this elimination.

Sources

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    In which year, and with what kind of attacks (classical or quantum), were SIKE and Rainbow broken?

  2. 02Recall

    What is the difference between how SIKE was removed from the NIST process (eliminated from Round 4) and how Rainbow was (not selected in Round 3)?

  3. 03Scenario

    A colleague says 'If SIKE was broken, Kyber can be broken too.' How do you answer, using the difference between the two algorithms' mathematical foundations?

  4. 04Hostile

    An auditor asks 'Two PQC algorithms collapsed before becoming standards. Isn't that enough reason not to trust the whole program?' Explain how the NIST process frames these collapses as a success.

Project linkContributes to the risk section of Project 4 (capstone) as a version of the 'unselected/eliminated candidate' risk different from HAWK (self-withdrawal); the concrete rationale for why only FINAL-status algorithms (ML-KEM, ML-DSA, SLH-DSA) should go into production in the migration roadmap.