Paper 2025/1916

Graeffe-Based Attacks on Poseidon and NTT Lower Bounds

Ziyu Zhao, Tsinghua University
Antonio Sanso, Ethereum Foundation
Giuseppe Vitto, University of Luxembourg
Jintai Ding, Xi’an Jiaotong-Liverpool University, Basque Center For Applied Mathematics
Abstract

Poseidon and Poseidon2 are cryptographic hash functions crafted for efficient zero-knowledge proof systems and have seen wide adoption in practical applications. We introduce the use of the Graeffe transform in univariate polynomial solving within this line of work. The proposed method streamlines the root recovery process in interpolation attacks and achieves several orders of magnitude acceleration in practical settings, enabling a new and more efficient class of attacks against Poseidon targeting round-reduced permutations and constrained input/output instances. We release open-source code and describe our method in detail, demonstrating substantial improvements over prior approaches: reductions in wall time by a factor of $2^{13}$ and in memory usage by a factor of $2^{4.5}$. Memory-access costs for NTTs turn out to be a dominant barrier in practice. And we prove that this cost increases at least as the $4/3$-power of the input size (up to logarithmic factors), which suggests the commonly used pseudo-linear cost model may underestimate the true resource requirements. This behavior contrasts with multivariate equation solving, whose main bottleneck remains finite-field linear algebra. We argue that, when selecting parameters, designers should account for interpolation-based attacks explicitly, since their practical hardness is determined by different, and sometimes stronger, resource constraints than those of multivariate techniques.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
PoseidonAlgebraic attackCryptanalysisRoot-findingGraeffeInterpolationCICOZero-KnowledgeHashNTT
Contact author(s)
ziyuzhao0008 @ outlook com
antonio sanso @ ethereum org
giuseppe vitto @ uni lu
jintai ding @ gmail com
History
2025-10-17: approved
2025-10-14: received
See all versions
Short URL
https://ia.cr/2025/1916
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1916,
      author = {Ziyu Zhao and Antonio Sanso and Giuseppe Vitto and Jintai Ding},
      title = {Graeffe-Based Attacks on Poseidon and {NTT} Lower Bounds},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1916},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1916}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.