The International Association for Cryptologic Research (IACR) was forced to void the results of its board and officer elections after a critical cryptographic key required to decrypt the electronic ballots was lost. The election, conducted using the Helios voting system, relied on a design where three trustees each held a portion of the decryption key, ensuring that no two could collude to alter results. However, one trustee irretrievably lost their private key, making it technically impossible to access or verify the final vote tally.
In response, the IACR decided to rerun the election and announced changes to its key management process to prevent similar incidents in the future. The new approach will require only two out of three key shares to decrypt results, reducing the risk of a single point of failure. The trustee responsible for the lost key has resigned and been replaced, and the new election is scheduled to run from November 21 to December 20. The incident highlights the operational risks associated with cryptographic key management, even in organizations specializing in security and cryptology.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Following the loss of the key and cancellation of the original results, IACR decided to rerun the election. The rerun was reported as the organization's remedy for the failed vote-counting process.
IACR canceled the election results after an official lost the secret/decryption key needed to open and count the encrypted ballots. Without the key, the organization could not verify or tally the votes from the completed election.
The International Association for Cryptologic Research conducted a board election using an online system in which ballots were encrypted and required a secret key to be decrypted for counting. This election occurred before the later disclosure that the key had been lost.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.