Researchers Found Flaws in Seven Cryptographic Hash Functions

The discovered vulnerabilities impact proposed next-generation security standards for commercial data encryption.

Updated on Sept. 22, 2026 in Cybersecurity

Bold vector editorial illustration of interlocking crystalline prisms, representing digital data structures, in a clean, high-contrast, multi-colored geometric style.
Researchers identified structural vulnerabilities in seven cryptographic hash functions submitted for future commercial encryption standards, prompting further security benchmark review. AI Illustration. Upload story photo >

Researchers have identified structural weaknesses in seven hash functions submitted to the Next-generation Commercial Cryptographic Algorithms Program. These findings represent a significant evaluation of security protocols intended for future commercial implementation.

Why it matters

The analysis informs the security requirements of the Institute of Commercial Cryptography Standards as they develop new cryptographic benchmarks. Identifying these vulnerabilities prior to adoption prevents the potential compromise of data integrity for future systems.

The analysis revealed that MoFang and Neulaser hash functions contain explicit collision vulnerabilities across all variants. Additionally, CHIME-512 and CHAMP reach success probabilities for collision attacks exceeding 0.39.

The players

Institute of Software Chinese Academy of Sciences

A research institution focused on computer science and cryptography with expertise in evaluating security protocols.

Institute of Commercial Cryptography Standards

A regulatory body responsible for establishing requirements for the Next-generation Commercial Cryptographic Algorithms Program.

The details

Researchers at the Institute of Software Chinese Academy of Sciences identified flaws by tracing message differences and state updates. The QSH hash function contains a core permutation that preserves a binary subspace—a specific set of values within a coordinate system—of dimension 16w throughout all rounds. Further analysis showed the Cuishen hash function's message expansion preserves a cyclic shift of eight binary coordinates across all 64 rounds, while WChain message expansions maintain invariant sets.

Timeline

  1. September 22, 2026: Analysis report published detailing the security vulnerabilities.

The Tech Race

The report evaluates candidates submitted to the Next-generation Commercial Cryptographic Algorithms Program to determine their viability for mass-market deployment. These results force a re-evaluation of the current candidate pool against established cryptographic security benchmarks.

These findings currently affect developers and engineers monitoring the standardization process for upcoming cryptographic requirements. There is no immediate impact on existing systems until the institute formally adopts or rejects these specific algorithms.

The takeaway

The research serves as a critical stress test for new cryptographic primitives being vetted for public commercial use. Stakeholders should monitor future updates from the Institute of Commercial Cryptography Standards to see which hash functions are cleared for inclusion in the final program.

Further reading

Explore more ongoing research in Cybersecurity to understand how standards evolve.

More information

Review the full cryptographic algorithm analysis paper for technical implementation details.

Researchers Found Flaws in Seven Cryptographic Hash Functions