IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
07 February 2026
IMDEA Software Institute, Madrid, Spain
Requirements
- BSc, MSc or PhD in Computer Science, Mathematics, or a closely related field
- Solid software engineering background, including API design, writing unit tests, and software documentation.
- Experience with C and Python languages (links to contributed projects, e.g., open-source repositories, are welcome in your CV)
- Foundations in algorithms and mathematics
- Foundational knowledge of computer architecture and microarchitecture (in particular, how they affect software performance)
- Basic knowledge of software optimization techniques (low-level programming with Intrinsics, compiler optimization options, and software profiling). Previous experience with it is highly desirable but not required.
Desirable Qualifications
- Prior experience implementing cryptographic primitives or protocols
- Ability to read and understand cryptography research papers Interest in bridging theoretical cryptography and practical implementations
- Experience with packaging and deploying Python projects.
Closing date for applications:
Contact: Dario Fiore
More information: https://software.imdea.org/careers/2026-01-programmer-verifhe/
IMDEA Software Institute, Madrid
The IMDEA Software Institute invites applications for a research internship in cryptography. The successful applicant will join the cryptography research team and contribute to the design and implementation of advanced cryptographic protocols, with an emphasis on practical and experimental aspects.
Who should apply?
Required qualifications:- BSc or MSc in Computer Science, Mathematics or a closely related field (completed or currently enrolled).
- Programming experience in C and Python (links to contributed projects, e.g., open-source repositories, are welcome in your CV).
- Familiarity with cryptography (e.g., through university-level coursework or equivalent experience).
- Foundations in algorithms and mathematics.
- Ability to read and understand cryptography research papers.
- Prior experience implementing mathematical algorithms or cryptographic protocols (in particular zero-knowledge proofs and fully homomorphic encryption).
- Knowledge of computer architecture and microarchitecture (in particular, how they affect software performance), and software optimization techniques.
Closing date for applications:
Contact: Dario Fiore
More information: https://software.imdea.org/careers/2026-01-intern-verifhe/
The Cyprus Institute
Post-Doctoral Research Fellow in Quantum Computing, Cryptography and Number Theory
at the Computation-based Science and Technology Research Centre (CaSToRC), The Cyprus Institute — ERA Chair QUEST.
The Cyprus Institute (CyI) invites applications for a post-doctoral research fellow within the EU-funded ERA Chair project QUEST: Quantum Computing for Excellence in Science and Technology, based at CaSToRC in Cyprus.
This position offers a unique opportunity to conduct original research at the forefront of quantum computing and quantum-era cryptography. The successful candidate will work on emerging problems at the interface of number theory, cryptography, and quantum computation, contributing to the development of new concepts, methods, and paradigms.
The role is well suited to candidates seeking interdisciplinarity and early involvement in a fast-growing research area, within an internationally connected and collaborative environment.
Qualifications
- PhD in Mathematics, Computer Science, Physics, Quantum Information, or a closely related field.
- Strong research potential and independence; experience with quantum programming or cryptography is an advantage.
Appointment
Full-time (18-month contract, renewable subject to performance and funding).
How to apply
Via the Cyprus Institute online recruitment portal.
Closing date for applications:
Contact:
Contact: Dr Eleni Agathocleous, Assistant Professor, CaSToRC, The Cyprus Institute
https://www.cyi.ac.cy/index.php/castorc/about-the-center/castorc-our-people/itemlist/user/1523-eleni-agathocleous.html
More information: https://onlinerecruitment.exelsyslive.com/?c=6e7274a2-8eba-4bea-905b-06f790eeb566&v=2026/0384
University of Warsaw, Poland
The Faculty of Mathematics, Informatics and Mechanics of the University of Warsaw (MIM UW) invites applications for the positions of Assistant Professor in Computer Science, starting on 1st October 2026 or 1st February 2027.
MIM UW is one of the leading Computer Science faculties in Europe. It is known for talented students (e.g., two wins and multiple top tens in the ACM International Collegiate Programming Contest) and strong research teams, especially in algorithms, logic and automata, algorithmic economy, and computational biology. There is also a growing number of successful smaller groups in diverse areas including cryptography, databases and knowledge representation, distributed systems, and machine learning. Seven ERC grants in Computer Science are running at MIM UW at the moment.
In the current call, 7 positions are offered (follow the links for more details):
- Samuel Eilenberg Assistant Professor (2 positions; reduced teaching and increased salary);
- Assistant Professor (3 positions; research and teaching);
- Assistant Professor in Systems, Programming Languages or Machine Learning (1 position; research and teaching; increased salary);
- Assistant Professor (1 position; teaching only).
Deadline for applications: 20th February 2026.
Closing date for applications:
Contact: Filip Murlak ([email protected]) or Oskar Skibski ([email protected]).
More information: https://jobs.uw.edu.pl/en-gb/offer/WMIM_2026/field/ADIUNKT/
Cryspen
Tasks
- Implement new cryptographic primitives and protocols for Cryspen products
- Maintain Cryspen's cryptographic software
- Integration of Cryspen products
- Proficient in cryptography or math
- Comfortable working in a distributed team
- Professional software development experience with Rust or C/C++
Closing date for applications:
Contact: Franziskus Kiefer
More information: https://join.com/companies/cryspen/15569089-cryptography-engineer
06 February 2026
Yechu Zhang, Yuxuan Chu, Yaodong Wei, Yueqin Dai, Qiu Shen, Jing Tian
Thomas den Hollander, Marzio Mula, Daniel Slamanig, Sebastian A. Spindler
A natural question that remained open is whether sticking with the modular polynomial-based approach, but switching to other candidates of modular polynomials, and in particular Atkin and Weber polynomials, is possible and gives improvements and flexibility. In this paper we show that the use of the Atkin modular polynomials enables the use of degrees not covered by existing works and improves the number of constraints for $\ell > 2$ by up to $27\%$, while the Weber polynomials allow up to $39\%$ sparser constraint systems than the current state of the art. As in our prior work on canonical modular polynomials, the adaption of well-known results to the Atkin and Weber modular polynomials also requires some technical work, especially when going to positive characteristic. To this end we expand and optimize our previous resultant-based methodology, resulting in much simpler proofs for our multiplicity theorems.
Nadim Kobeissi
We examine five vulnerabilities across these libraries. The first, a platform-dependent cryptographic output failure in SHA-3 intrinsics discovered by an independent researcher in November 2025, set the stage for our own audit, which identified four additional defects: a missing mandatory validation for X25519 Diffie-Hellman outputs, a nonce reuse vulnerability via integer overflow, ECDSA signature malleability due to absent low-S normalization, and an Ed25519 key generation defect that reduces seed entropy.
We analyze why each defect fell outside the scope of the formal verification methodology employed, identify a structural pattern we term the verification boundary problem, and argue that the gap between marketing claims of verification completeness and the engineering reality of partial verification constitutes a systemic risk for adopters of formally verified cryptographic software. Our findings suggest that formal verification, while valuable for the specific properties it targets, must be complemented by traditional engineering practices and communicated with precision about its actual scope, lest it become a form of security theater.
Tako Boris Fouotsa, Marc Houben, Gioella Lorenzon, Ryan Rueger, Parsa Tasbihgou
Bowen Jiang, Guofeng Tang, Haiyang Xue
We bridge this gap by introducing a three-round threshold ECDSA scheme with constant outgoing communication based on threshold CL encryption. Additionally, we enhance our basic scheme with robustness while maintaining the number of communication rounds, albeit at the cost of non-constant outgoing communication. Our implementation demonstrates that the basic scheme achieves optimal runtime and communication costs, while the robust variant reduces the communication rounds required by Wong et al.'s scheme, incurring only a small additional cost in small-scale settings.
Paco Azevedo-Oliveira, Jordan Beraud, Pierre Varjabedian
Although pre-quantum threshold signature algorithms have been extensively studied, the state of the art in the creation of post-quantum threshold algorithms remains sparse. Most studies focus on signature algorithms based on structured lattice problems. In particular, few papers have studied the creation of a threshold algorithm based on UOV, despite the simplicity of the scheme.
This paper proposes various algorithms for a set of parties to solve a shared linear system $Ax= y$ in finite fields of low characteristic.
The first two algorithms securely calculate the determinant of a shared matrix. The first uses recent theoretical results on Newton's polynomials while the second adapts an algorithm by Samuelson and Berkowitz. From these algorithms, we can deduce two algorithms to solve the corresponding linear system. The last algorithm revisits an existing state-of-the-art algorithm by adding noise to the revealed matrix rank. We show that the resulting leakage will be hard to exploit.
These two algorithms enable new threshold instantiations of UOV and UOV-based schemes, in particular MAYO.
Yongbo Hu, Chen Zhang, Guomiao Zhou
Martin R. Albrecht, Russell W. F. Lai, Eamonn W. Postlethwaite
1. If there exists an efficient algorithm for hinted ISIS that outputs solutions a constant factor longer than the hints, then there exists a single-exponential time and polynomial memory zero-centred spherical Gaussian sampler solving hinted SIS with norm a constant factor shorter than the hints.
2. Assume the existence of a chain of algorithms for hinted ISIS each taking as input Gaussian hints whose norms decrease by a constant factor at each step in the chain, then there exists a single-exponential time and polynomial memory algorithm for SIS with norm a quasilinear factor from optimal.
The existence of such hinted ISIS solvers implies single-exponential time and polynomial memory algorithms for worst-case lattice problems, contradicting a conjecture by Lombardi and Vaikuntanathan (CRYPTO’20) and all known algorithms. This suggests that hinted ISIS is hard.
Apart from advancing our understanding of hinted lattice problems, an immediate consequence is that signing the same message twice in GPV-style [Gentry–Peikert–Vaikuntanathan, STOC’08] schemes (without salting or derandomisation) likely does not compromise unforgeability. Also, cryptanalytic attempts on the One-More-ISIS problem [Agrawal–Kirshanova–Stehlé-Yadav, CCS’22] likely will need to overcome the conjectured space-time hardness of lattices.
Michel Abdalla, Brent Carmer, Muhammed El Gebali, Handan Kilinc-Alper, Mikhail Komarov, Yaroslav Rebenko, Lev Soukhanov, Erkan Tairi, Elena Tatuzova, Patrick Towa
This work introduces Bitcoin PIPEs v2, an upgrade to the original Bitcoin PIPEs approach focusing on emulating missing covenant functionality practically without requiring a soft fork. At its core, a PIPE v2 uses a witness encryption (WE) scheme to lock a Bitcoin private key under an NP statement. The key (and thus the ability to spend the associated coins) can be recovered only by a participant who provides a valid witness (e.g., a SNARK proof) satisfying that statement. Once unlocked, the mechanism outputs a standard Schnorr signature indistinguishable from any other Bitcoin signature. From Bitcoin’s perspective, transactions appear entirely ordinary; yet they are cryptographically guaranteed to enforce arbitrary off-chain logic.
We formalize how PIPEs v2 enable arbitrary spending conditions on Bitcoin by enforcing predicates on signatures through cryptography, without requiring any consensus changes. We introduce a new primitive, the Witness Signature (WS), which captures conditional signing under hard relations. We show that a PIPE instantiated with a WE scheme and a standard digital signature scheme enables programmable covenants and SNARK-verifiable conditions on Bitcoin—entirely without soft forks, trusted parties, or interactive fraud-proof mechanisms such as those used in BitVM constructions.
Finally, we explore Arithmetic Affine Determinant Program (AADP)-based witness encryption as a concrete and promising research direction for realizing PIPEs. AADPs provide an explicit arithmetic framework for enforcing SNARK-verifiable NP predicates within the PIPE architecture.
This work presents a new, second-generation construction of PIPEs (PIPEs v2) for Bitcoin, extending and replacing the earlier formulation proposed in [Kom24].
Antonin Leroux
Liyan Chen, Zhengzhong Jin, Daniel Wichs
We obtain both positive and negative results for SNAPs. - Adaptive SNAPs for P and NP: For any $\epsilon \in (0, 1)$, we construct the first adaptively sound SNAPs for P with $\epsilon$-proximity based on standard assumptions: LWE or subexponential DDH or DLIN over bilinear maps. Our proof size, verifier’s query complexity, and verification time are $n^{1/2 + o(1)}\cdot \mathsf{poly}(\lambda)$, where $n$ is the length of the statement and $\lambda$ is the security parameter. By additionally assuming sub-exponentially secure indistinguishability obfuscation, we upgrade this result to SNAPs for NP with essentially the same parameters.
Previously, we only had non-adaptively sound SNAPs for P in the designated verifier setting with $O(n^{1-\delta})$ proof size, query complexity, and verification time for some constant $\delta > 0$.
- Lower Bound: We show that our parameters in the adaptive soundness setting are nearly optimal, up to an $n^{o(1)} \cdot \mathsf{poly}(\lambda)$ factor: in any adaptive SNAP for P, the product of proof size and verifier query complexity must be $\Omega(n)$. Our lower bound is unconditional.
- Fully Succinct Non-adaptive SNAPs for NP: For any constant $\epsilon \in (0, 1)$, we construct the first non-adaptively sound SNAPs for NP with $\epsilon$-proximity, based on learning with errors and indistinguishability obfuscation. The proof size, verifier’s query complexity, and verification time in our constructions are fixed polynomials in the security parameter. We also show that restricting such SNAPs to just P would already imply non-adaptively sound SNARGs for NP.
Central to our SNAP constructions is a new notion of commitment of proximity, which enables sublinear-time verification of the commitment. To derive our unconditional lower bound, we adopt and generalize theorems from oracle-presampling techniques in the random oracle literature. Both techniques may be of independent interest.
Christopher Harth-Kitzerow, Jonas Schiller, Nina Schwanke, Thomas Prantl, Georg Carle
This work comprehensively analyzes over 50 MPC applications to identify the core algorithmic structure most common in real-world MPC applications. From this analysis, we derive six reference use cases and implement these across four state-of-the-art MPC frameworks: HPMPC, MPyC, MP-SPDZ, and MOTION. We develop an open-source benchmarking framework that evaluates these implementations under varying network conditions, including bandwidth constraints, latency, packet loss, and input sizes.
Our work presents the first systematic cross-framework evaluation of MPC performance based on real-world use cases across diverse network conditions and MPC security models. Thus, our comprehensive analysis yields novel insights into practical MPC performance and provides evidence-based recommendations for framework selection across different operational contexts.
Pierre Civit, Daniel Collins, Vincent Gramoli, Rachid Guerraoui, Jovan Komatovic, Manuel Vidigueira, Pouriya Zarbafian
This paper presents $\tau_{zk\text{-}scr}$, a universal compiler that circumvents such limitations. The compiler transforms any protocol $\mathcal{P}$, that is secure against semi-honest crash-failure adversaries, into a Byzantine-tolerant, accountable counterpart $\bar{\mathcal{P}}$. Essentially, we devise $\tau_{zk\text{-}scr}$ by deconstructing the celebrated CLOS compiler (STOC 2002), observing that each resulting component is ``easily accountable'', and globally propagating the accountability through the reconstruction. The guarantees provided by $\tau_{zk\text{-}scr}$ are defined with respect to a resilience threshold $t_{\epsilon} = \lceil n (\frac{1}{3}-\epsilon) \rceil - 1$, for any $\epsilon \geq 0$. $\bar{\mathcal{P}}$ preserves the hyperproperties of $\mathcal{P}$, including privacy, input-independence, correctness, and output delivery, whenever $f \leq t_{\epsilon}$.
If $f > t_{\epsilon}$, then either: (1) $\bar{\mathcal{P}}$ emulates $\mathcal{P}$, in the sense that all its hypersafety properties are preserved, though output delivery may not occur; or (2) all correct processes obtain externally verifiable proofs of misbehavior involving a significant subset of faulty parties. By adjusting its parameters, $\tau_{zk\text{-}scr}$ achieves various trade-offs. Assuming a transparent setup, for any strictly positive constant $\epsilon \in \Omega(1)$, the most efficient instantiation provides security against a 1-delayed-adaptive adversary (i.e., where corruption decisions are postponed just long enough to allow messages in transit to be delivered) with $o(n^2)$ multiplicative communication overhead.
Our results are formalized and proven following the Accountable Universal Composability (AUC) blueprint (S&P 2023), an extension of UC designed to support modular analysis of accountability guarantees.
Pousali Dey, Rittwik Hajra, Subha Kar, Soumit Pal
We remove the dependence on any designated tracer and propose Collaborative Traceable Secret Sharing ($\mathsf{CTTSS}$), which eliminates the private trace key and the private verification key. Instead, tracing requires collaboration from a threshold number of parties, and verification is fully public. We define the $\mathsf{CTTSS}$ framework, along with its security notions, and present two efficient collaborative traceable secret sharing schemes based on the classical Shamir and Blakley schemes. Both achieve secrecy, traceability, and non-imputability, with minimal share size overhead and polynomial-time tracing effectively eliminating the need for a designated tracing authority.