Researchers reported that HAWK, a lattice-based digital signature candidate in NIST's additional post-quantum signature process, can be weakened when an attacker knows a nontrivial automorphism of the underlying integer lattice. In the paper "HAWK: Having Automorphisms Weakens Key", the authors show that for cyclotomic rings whose degree is a power of two, the search rank-2 module Lattice Isomorphism Problem used by HAWK can be reduced to an instance with at most half the rank, accelerating key-recovery attacks by at least a quadratic factor and effectively cutting the scheme's security margin by roughly half in bits.
The work does not claim a full practical break of HAWK, but it identifies a new attack avenue tied to the automorphism group of the lattice structure. The paper also links its findings to earlier ASIACRYPT 2024 research by Luo et al., which identified a symplectic automorphism that broke HAWK's original omSVP assumption; the HAWK team subsequently revised that definition in its second-round NIST additional-signatures submission. HAWK remains listed among NIST's additional digital signature candidates, making the result relevant to organizations tracking the resilience of post-quantum signature schemes under evaluation.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The paper "HAWK: Having Automorphisms Weakens Key" reports that knowing a nontrivial automorphism can reduce certain HAWK lattice isomorphism instances to at most half the rank, speeding key-recovery attacks by at least a quadratic factor and effectively halving security bits. The authors state this does not currently break HAWK but reveals a new theoretical attack avenue.
A public HAWK project website is available, providing a reference point for the scheme and its materials.
NIST's project page for additional post-quantum digital signature schemes lists the Round 3 candidates, including HAWK, as part of its standardization process for additional signatures.
A new paper presents a deterministic polynomial-time reduction from HAWK key recovery to polynomially many exact SVP oracle calls in dimension n/2 + 1, improving prior attack costs. The authors estimate reduced gate counts for HAWK-512 and HAWK-1024 and report recovering HAWK-256 secret keys end-to-end in a few hours on a single server.
According to the ePrint paper, the HAWK team revised the omSVP definition in its second-round NIST additional signatures submission to account for a symplectic automorphism identified by prior work from Luo et al. at ASIACRYPT 2024.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
eprint.iacr.org
Open sourcehawk-sign.info
Open sourcecsrc.nist.gov
Open sourceanthropic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.