Paper 2026/150
Claiming bounties on small scale Poseidon and Poseidon2 instances using resultant-based algebraic attacks
Abstract
In november 2024, the Ethereum foundation (EF) issued a bounty program with challenges on Poseidon and Poseidon2. The goal of these challenges is to find CICO solutions on different round-reduced instances of Poseidon and Poseidon2, defined on different prime fields. We denote the four main instances Poseidon-256, Poseidon2-64, Poseidon2-31m and Poseidon2-31k. In the challenges, the goal is to solve CICO-1 for Poseidon-256 and Poseidon-64, and CICO-2 for Poseidon-31m and Poseidon-31k. We found CICO solutions to the first 3 proposed instances of Poseidon2-31m and Poseidon2-31k, along with solutions for the first two Poseidon-256 instances. These solutions have been confirmed to be correct and eligible for bounty by the Ethereum fundation, except for the first instance of Poseidon-256, which was claimed by another team before us. In order to solve the instances of Poseidon2-31m and Poseidon2-31k, we used a new resultant-based approach, whereas our attacks on Poseidon-256 only relies on already-known univariate root finding.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- oseidonCICO ProblemCryptanalysishash functionpolynomial solvingalgebraic attackresultant
- Contact author(s)
-
antoine bak @ inria fr
aurelien boeuf @ inria fr
mael hostettler @ telecom-sudparis eu
guilhem jazeron @ inria fr - History
- 2026-02-11: revised
- 2026-01-30: received
- See all versions
- Short URL
- https://ia.cr/2026/150
- License
-
CC BY-SA
BibTeX
@misc{cryptoeprint:2026/150,
author = {Antoine Bak and Augustin Bariant and Aurélien Boeuf and Maël Hostettler and Guilhem Jazeron},
title = {Claiming bounties on small scale Poseidon and Poseidon2 instances using resultant-based algebraic attacks},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/150},
year = {2026},
url = {https://eprint.iacr.org/2026/150}
}