Researchers Found Flaws in Proposed Cryptographic Algorithms
Seven proposed hash functions were found to be susceptible to collision vulnerabilities in a recent analysis.
Updated on Sept. 22, 2026 in Cybersecurity

Researchers have identified structural weaknesses in seven hash functions submitted for the Next-generation Commercial Cryptographic Algorithms Program. These findings raise concerns regarding the security of potential standards currently under review.
Why it matters
The Institute of Commercial Cryptography Standards requested feedback on draft requirements, and these vulnerabilities demonstrate that the submitted algorithms do not meet necessary security benchmarks. Identifying these flaws early is critical to preventing the adoption of compromised encryption systems.
CHIME-512 allows collisions with 2^64 evaluations, while CHAMP requires up to 2^384 evaluations. Additionally, the QSH core permutation preserves a 16w binary subspace and Cuishen features message expansion issues over 64 rounds.
The players
Institute of Software Chinese Academy of Sciences
This is a research institution responsible for conducting the study and identifying the cryptographic weaknesses.
Institute of Commercial Cryptography Standards
This organization is currently overseeing the Next-generation Commercial Cryptographic Algorithms Program and soliciting public feedback.
The details
Researchers at the Institute of Software Chinese Academy of Sciences identified flaws through the analysis of state updates, invariant subspaces, and determinant constraints. The identified hash functions, including MoFang, Neulaser, CHIME-512, CHAMP, QSH, WChain, and Cuishen, all displayed exploitable collision vulnerabilities.
Timeline
September 22, 2026: The analysis report was published.
The Tech Race
This study marks a significant challenge to the selection process of the Next-generation Commercial Cryptographic Algorithms Program. It highlights the ongoing arms race between cryptographers developing new standards and analysts seeking to uncover mathematical vulnerabilities.
For developers and systems architects, these findings serve as a warning to avoid integrating these specific algorithms into production environments. The research ensures that only robust, tested encryption protocols reach the public, ultimately protecting digital privacy.
The takeaway
Robust peer review remains the most effective defense against the adoption of flawed security standards in the tech industry. Analysts and researchers continue to play a vital role in identifying mathematical weaknesses before they can be exploited by malicious actors.
Further reading
For more information on current developments in digital protection, visit the /tech/cybersecurity/ section.
More information
Review the full cryptographic algorithm analysis paper for technical details on the discovered flaws.







