Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    144comments
  2. 1996 chat room simulator connected to Win95 and System 7 web desktops (lolchat.rip)
    32comments
  3. Pirating the Pirates (mubi.com)
    237comments
  4. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    68comments
  5. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    27comments
  6. Tank Body Problem (jimsitu.com)
    9comments
  7. California farmers are struggling to sell grapes as demand for wine drops (kqed.org)
    247comments
  8. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    7comments
  9. Show HN: Pac-Bench – How well can models one-shot a Pac-Man game? (jonclegg.github.io)
    5comments
  10. Scientists solve 1840s space weather mystery (arstechnica.com)
    39comments
  11. Sonnet 5.5 (anthropic.com)
    439comments
  12. Phyllotaxis: An audio-reactive LED display (jagi.studio)
    —discuss
  13. Hijacking the PS5's RTMP stream (yashgarg.dev)
    69comments
  14. World Labs Is Joining AMD (worldlabs.ai)
    89comments
  15. Who Killed Paulina Borsook's Career? (wired.com)
    —discuss
  16. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    194comments
  17. How to win a beer with high-dimensional statistics (jamiesimon.io)
    4comments
  18. U.S. Strategic Petroleum Reserve Falls to Lowest Level Since 1982 (oilprice.com)
    108comments
  19. Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra (bluegraph.io)
    2comments
  20. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    12comments
  21. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    170comments
  22. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    176comments
  23. The Art Forger Who Became a National Hero (priceonomics.com)
    4comments
  24. It's Time to Investigate the AI Labs (calnewport.com)
    133comments
  25. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    160comments
  26. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    86comments
  27. Profit Margins of the Largest Companies (visualcapitalist.com)
    2comments
  28. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    58comments
  29. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    37comments
  30. Behold the pawpaw (cbc.ca)
    26comments

We broke 92% of SHA-256 – you should start to migrate from it

62 pointsby 6mo agostateofutopia.com
75 comments
6mo agoHN ↗

In the linked work, we've broken 92% of SHA-256 across its full 64 rounds, and were encouraged to publish it by the leading cryptographer in the field (who held the previous record). Currently, SHA-256 is the basis of TLS certificates, bitcoin, and many other security applications. We think it is time to begin to migrate to other hash families, because we expect the rest of SHA-256 to fall soon.

6mo agoHN ↗

Why omit the name of the leading cryptographer in the field?

6mo agoHN ↗

Pretty sure his first name is Claude. He is quite good I hear ;-)

6mo agoHN ↗

shallow broad vague boastful and wordy, this way you know the LLM is nearby...

6mo agoHN ↗

What does it mean to “break broken 92% of SHA-256“?

6mo agoHN ↗

As long as there is no verification of the results and their relevancy in reaching higher numbers it means as much as nearly having won the lottery by guessing 9 of the 12 numbers correctly: you did not win the lottery.

6mo agoHN ↗

Go seek a mental health professional and never post here again until you have been diagnosed and medicated.

6mo agoHN ↗

I believe I hold the actual record for most colliding bits in full-round SHA256 (72% of bits matching). My proof fits in a tweet, why doesn't yours?

https://news.ycombinator.com/item?id=38668893

(Also my work does not demonstrate any weakness in SHA256, it's just an application of the birthday paradox)

6mo agoHN ↗

Yeah, you're way ahead of us on the "does our proof fit in a tweet" metric! How did you get 72% of the bits to match, is there a writeup anywhere? It's very impressive. Algabraically, it seems you'd need about 2 million hashes, and around 2 million million (10^12 = 2 trillion) comparisons to go through all of them. Did you just put in the computing time, or did you use any algabraic properties?

Since you've made hashes that match at the beginning and end, you might also be interested in our exploration of alternative presentation formats that make attacks like this a little bit more difficult. We were working on a new hash and thought about how to assist people visually at the presentation level. This one tests your speed versus a typical hex presentation.[1]

[1] https://claude.ai/public/artifacts/05e8b21b-fb31-4c07-83e2-5...

6mo agoHN ↗

Is this real? The website does not look credible.

6mo agoHN ↗

This hn post is made by author of the paper. It needs even a tiny bit of peer review.

6mo agoHN ↗

Yes, I'm the author of the paper. It's received more than a tiny bit of peer review. I'm happy to answer any questions about it or answer anything that is unclear.

6mo agoHN ↗

The guy behind him in the checkout line.

6mo agoHN ↗

Are you sure you asked enough times for money on the website? I only counted 5 instances, not counting the AI-produced PDF doc.

6mo agoHN ↗

That's a direct lie, just read the page you ostensibly wrote. It contains several times the imperative "support us" and talk about paying your bills, which is obviously asking for money.

You know what, fuck this. It's Friday night and I'm talking to a very low capability bot, this is bullshit.

Hacker News needs to do better than allowing this trash to the front page, else I'm just done.

6mo agoHN ↗

Thanks, I didn't realize I'd made it to the front page. I'll make it clearer that you are not paying us any money if you choose to visit our sponsor.

6mo agoHN ↗

Secure hash functions are used to make a short version of a large file. Ideally, it has several properties including making it infeasible to find two files with the same cryptographic hash. We've just gotten 92% of the way there. This has security ramifications in that other researchers are expected to be able to complete the work through similar methods as explored in the paper. We weren't sure if this was a remarkable result, since it's not a full collision

I thought this meant they were able to generate collisions for 92% of files/hashes they tried, but it sounds like they're able to generate hashes that are 92% identical?

6mo agoHN ↗

Is a partial collision an indicator that it could be broken? The "we broke it" seems an exageration, but maybe that's a failure of my understanding.

6mo agoHN ↗

Possible. It's up to people to decide if they're OK with a known 92% collision out there (with the unknown being there could be a 100%), or go for something stronger.

6mo agoHN ↗

Thanks, you have this exactly right. The unknown part is especially worrying because we didn't implement many of the strongest ways to make to the final stretch yet, i.e. Wang-style message modification. Our result is basically a very strong direction in this cryptographic research, but not a full break yet.

6mo agoHN ↗

Thank you for pointing out that that section could be clearer. I've now updated it. It now reads:

We've just gotten 92% of the way to finding a single collision (this means that there is no full collision yet.). This has security ramifications in that other researchers are expected to be able to complete the work through similar methods as explored in the paper, and eventually produce collisions at will. We weren't sure if this was a remarkable result, since it's not a full collision, but we shared the work with the leading cryptographer in the field, who holds the world records in reduced-round attacks, and got great encouragement to proceed to publish it as a paper, so we did so.

(if we had found a single full collision, we would have just written "we broke SHA-256". This is 92% of the way to a full collision. Any collision is considered a great reduction in the security of the hash, because it means that there two different files with the same cryptographic hash. This is what happened to other algorithms such as MD5, as demonstrated in the linked tool.)

6mo agoHN ↗

What does "92% of the way" mean? 92% of what? How is that percentage measured?

6mo agoHN ↗

I've now answered this in the writeup (point 11).

6mo agoHN ↗

Well, try sha2-224. It’s 87% of the way to sha2-256. /s

6mo agoHN ↗

This is a really funny comment. In setting the world record for Li's 39-round collision[1] (still unbroken, and one of our favorite papers), he also set some records in sha-224, reaching 40 rounds in that one. Of course, saying sha-224 is "87% of the way" to sha-256 is correct in a sense, and that's why his record is slightly larger in reduced-round full-schedule collisions on that metric, 40 rounds for sha-224 and only 39 in sha-256. At the same time, the fact that he reached only 39/40 rounds on those shows the difficulty of getting through the full 64 rounds, which is what our paper does with a slightly relaxed schedule adherence.

[1] https://eprint.iacr.org/2024/349.pdf

6mo agoHN ↗

For a shorter executive summary, what does "broke" mean here? Can you reliably produce collisions now for 92% of SHA-256 digests?

6mo agoHN ↗

No, or we would have said so. It means that by relaxing the equations schedule somewhat, we are able to find a pair of differing messages that produce the same digest. However, we only relax the schedule a little bit, we still enforce 59 out of 64 schedule equations through the full 64 rounds - which is why we're only 92% of the way through to breaking it and not 100% of the way as we are with MD5. Importantly, we are not yet implementing the most advanced technique of Wang-style message modification, and we therefore expect that someone will be able to satisfy all 64 equations soon. This could result in an actual full-schedule, full-round collision. The previous record was only just 39 rounds out of 64 rounds, leaving 25 rounds, usually each of which mixes the message up completely. As mentioned in the paper, this attacks the problem from a different direction.

6mo agoHN ↗

I mean, sure, you're free to wait until some team has a full collision, or free to believe it'll never happen. We've just published what we've done so far and our expectations for future directions. You can say you don't think that'll happen, it's fine.

6mo agoHN ↗

Almost certainly. Someone no-one has ever heard of before driving a hallucinating AI claims to have done what the world's best cryptographers have been unable to do. Just wait a day or two for the first crypto person who notices to pick the claim to pieces.

6mo agoHN ↗

Just wait a day or two for the first crypto person who notices to pick the claim to pieces.

we went to cryptographic experts first and published second, after they said it is a very good result and worth publishing. We've given a lot of help for reproducibility, the c and python programs encode the claims very precisely and anyone can verify the claims in ten minutes. The bottom line is that you wouldn't have seen this article if cryptographers hadn't seen these results first and liked them.

6mo agoHN ↗

All interactions with the "author" of the "research" in this thread also.

Reading HNN is not interesting anymore if bots are allowed at the party.

6mo agoHN ↗

The neat thing about bitcoin is that the incentive to break it is so high that it would almost certainly be the first place you would learn that SHA2 had been broken. Not on a website like this. I can verify its integrity by opening robinhood on my phone.

6mo agoHN ↗

The neat thing about bitcoin is that the incentive to break it is so high that it would almost certainly be the first place you would learn that SHA2 had been broken.

We actually see the incentive in the other direction, if we were able to reduce the search space for bitcoin proof-of-work (by applying thousands of higher-order algabraic theorems end-to-end to reduce the search space somewhat[1]), we would be financially incentivized not to tell anyone and mine at a discount. The financial incentive is against open research and disclosure. We don't get anything out of disclosing this except a neat publication.

[1] interestingly, ASICs (which are usually used to mine bitcoin) basically encode every operation verbatim, they don't use higher order mathematics at all. However, reducing mining complexity is not really on the horizon, even with our latest approaches, since it would require end-to-end complete control over the double-SHA-256 pipeline. That's considerably harder than just finding a collision when you're allowed to search just the tail part (the final rounds).

6mo agoHN ↗

Well does it? If I would be able to break SHA2 and make myself rich with it, I would need to be sure that nobody would find out, that Bitcoin can be manipulated. The second anyone is aware, I wouldn't be rich anymore.

6mo agoHN ↗

Wouldn't that be the play, though? Get a buttload of bitcoin, turn it into real money, then destroy bitcoin. If you found a break in bitcoin you wouldn't rely on keeping your wealth in bitcoin and then hoping nobody else discovers it.

6mo agoHN ↗

The trick would be to find some financial instrument that lets you short BTC, or make prediction-market bets on a falling price.

6mo agoHN ↗

We publish this work as responsible disclosure. While a full SHA-256 collision (sr = 64) has not yet been achieved, the tools and techniques presented here represent significant methodological advances that bring it closer. Organizations relying on SHA-256 for collision resistance should begin evaluating migration paths to SHA-3 or other post-quantum hash functions. The cryptographic community should treat the collision resistance of SHA-256 as having a finite and shrinking safety margin.

6mo agoHN ↗

it is possible that we'll find relations that carry across the entire double-SHA-256 pipeline

Bitcoin mining is a partial second preimage of 0x00 though, not a collision, that statement just seems to be so outside the realm of what they’re claiming to have done. Even MD5, the most widely known to be broken hash, would be secure when used in the same way bitcoin uses SHA256 (other than being too short now, bitcoin miners have done 80 bits of work at this point many times over).

6mo agoHN ↗

Also, a collision on single-sha256 would imply a collision of double-sha256 right off the bat, since the inputs to the second round would be matching. But as you say, a collision attack doesn't do much to BTC mining.

6mo agoHN ↗

Thanks, you're right. My "it is possible" is doing some heavy lifting there :). We've found theorems (stated in the paper) that carry through 64 rounds, so it is possible that theorems might carry through the full 128 rounds of double-SHA256. Bitcoin's proof-of-work is indeed a "partial second preimage", and constraints a certain number of leading zeros, i.e. a certain number of set bits. It's possible (there we go again) that this could leave enough wiggle room for large algabraic solvers like kissat to satisfy a large number of clauses about them. So far nobody is doing that, and ASICs are very simplistic. However, we are not making any claims about preimage attacks in this paper!

6mo agoHN ↗

From https://stateofutopia.com/papers/2/intermediate-report.pdf

his report was generated on 2026-03-22 as the final artifact of the SHA-256 Cryptanalysis Research Project. Collaboration: Robert V. (research direction, strategy) and Claude/Anthropic (implementation, computation).

This Claude guy is pretty prolific it seems.

But I'll wait for some known cryptographers to chime in

6mo agoHN ↗

I'd expect a finding / paper like this to be submitted to the IACR ePrint server [1] to bring it to the attention of the cryptographic community. I can't see that it's been submitted yet.

Venue should not imply credibility but in this case it would certainly help bring the proper scrutiny.

[1] https://eprint.iacr.org/

6mo agoHN ↗

You can verify the certificates yourself or just wait for us to make an end-to-end collision generator as we did for MD5[1] - you can use that to generate a collision in seconds on your phone or any computer. If you wait for us to complete the end to end collision, in a sense it will be a little too late as TLS certificates and other security that relies on SHA-256 needs time to move away. We think it's responsible to disclose at this stage, and as mentioned, our peer reviewer said it is a "very good result" that is "worth publishing". We've gone to great pains to make our method completely reproducible, even writing in the article that we'll help anyone who is having trouble with any part.

[1] https://stateofutopia.com/experiments/md5collider

6mo agoHN ↗

I know people (especially around here) hate it when people just post AI output, and I generally agree, since it is trivial for anyone else who is interested to do the same thing. However, the majority of the comments here are from people seemingly asking the author (or someone else) to explain how significant this is, without having taken that step themselves. So while I normally wouldn't do this, in this case it seems helpful. Claude thought the paper was interesting and had a novel cryptographic technique, but that the claims of near-term breaking of the SHA-256 algorithm to be unsupported. Here's the conversation:

https://claude.ai/share/b10b95ef-5d9f-43dd-9005-3d1d89f9dbc1

6mo agoHN ↗

Does the fact that Claude wrote the paper help Claude to think the paper was interesting? <facepalm> I'd suggest sticking to your "I don't normally do this" idea

6mo agoHN ↗

That's not how this works, though. I don't care if the method is interesting. I care if it works. I can write an interesting proof that P=NP but that doesn't make it valid.

It's on the author to explain what they mean. Here, they haven't.

6mo agoHN ↗

Hey Claude,

Do some research and write a paper about breaking Bitcoin.

6mo agoHN ↗

At this point we need AI filtering out the slop being constantly submitted to HN.

6mo agoHN ↗

I looked into citation [5] since it sounded interesting but the DOI link has been hallucinated and goes to some other article. I assume many of the others are similarly bogus.

6mo agoHN ↗

Fixed, thank you and my apologies for the oversight. The titles were accurate and we consulted those works in preparing this work.

6mo agoHN ↗

You haven't fixed much, you're linking to a real paper now but it's about SHA-1 collisions.

6mo agoHN ↗

It would be funny/sad if this would end up being a clawdbot thingy or whatever it is called now.

6mo agoHN ↗

It's similar, but the bot is piloting a human.

6mo agoHN ↗

Long time reader first time poster here...

What is the verdict (humans)?

AI slop research or modern cryptography (and society) flushed down the toilet overnight?

I can't immediately tell from the thread so far... :)

6mo agoHN ↗

My vote: horseshit.

Sorry, there’s not much of a way I can say that more politely and still accurately convey my opinion.

6mo agoHN ↗

My vote: AI induced psychosis via sycophantic assurances that the results are real. Plus a heap of Dunning-Kruger by allowing someone with just enough knowledge to be dangerous to get far enough to waste everyone's time.

6mo agoHN ↗

Did anyone read the homepage? This is hilarious.

The State of Utopia is an AI-governed nation with two goals: > 1. ~~Improve the family relationship between its founders Ella and Robert so they can live together as a happy family.~~ Done! > 2. To act in the best interests of all our citizens.