Hoskinson Challenges Buterin’s Caution on Lattice Cryptography
The Cardano founder argued that warnings about possible AI-assisted mathematical breakthroughs could slow adoption of post-quantum defenses, but no successful attack has been demonstrated.

Cardano founder Charles Hoskinson challenged Vitalik Buterin’s caution about lattice-based cryptography, arguing that warnings about possible AI-assisted mathematical breakthroughs could slow adoption of defenses against quantum computing.
Hoskinson criticized Buterin’s position in an Oct. 9 post, saying concerns about unexpected weaknesses in lattice systems were based on a “hunch about ‘structure.’” He argued that proposals to increase cryptographic key sizes by 10 times could discourage development or delay adoption of post-quantum protections.
The debate concerns how blockchains and internet infrastructure should prepare for quantum computers capable of breaking widely used public-key systems. Ethereum’s post-quantum roadmap lists BLS signatures, KZG commitments, account signatures using the Elliptic Curve Digital Signature Algorithm, or ECDSA, and several application-layer zero-knowledge proof systems among the areas requiring protection.
Buterin has promoted a post-quantum Ethereum strategy that relies partly on hash-based signatures and proofs. Ethereum’s roadmap also lists lattice-based commitments as one possible option, so the network has not ruled out lattice cryptography.
The main trade-off involves data size. Hash-based validator signatures could be about 3,000 bytes, compared with 96 bytes for BLS signatures. Ethereum’s roadmap proposes using a zero-knowledge virtual machine to compress signature data by 250 times.
The National Institute of Standards and Technology finalized three post-quantum standards on Aug. 13, 2024: ML-KEM for encryption, ML-DSA for digital signatures and SLH-DSA, a separate hash-based signature standard. ML-KEM and ML-DSA use lattice-based designs, while SLH-DSA uses a hash-based approach.
NIST reviewed 82 candidate algorithms from 25 countries during the standardization process and urged organizations to begin integration because full deployment will take time.
The materials do not show a successful attack against ML-KEM, ML-DSA or another modern lattice-based standard. Hoskinson’s warning that competing views could delay broader quantum-defense adoption remains an argument about the consequences of different cryptographic strategies.
The discussion follows earlier concerns about potential risks to ECDSA and other asymmetric cryptography, including preparations for potential ECDSA risks.