Paper 2026/1542

Signing-Key Recovery from Unsalted Root Expansion and Salt-Binding Repair for MQOM v2

José Luis Delgado
Abstract

We give the first passive classical EUF-CMA attack on MQOM v2 in which an optimal three-record parity-indexed XOR triangle detects every usable collision, recovers the complete signing key, and produces a fresh-message forgery. In MQOM v2, every correlated-GGM root is derived from a fresh $\lambda$-bit master seed using a fixed PRG call with zero salt, while a public opening reveals either the corresponding root or its XOR with a fixed prefix of the long-term MQ witness. The resulting root functions are shared by all signatures, keys, salts, and v2 releases, so repeated master seeds expose linear equations in the witness. In Category I at the permitted $Q=2^{64}$ signing-query boundary, the attack has birthday-regime success $0.393395296381$ with error $O(2^{-64})$. A rank-two extension recovers two unrelated keys, while reusable global tables attain membership-certified lower bounds of $0.632030733547$ for the complete triangle and $0.776706354579$ for the record-optimal one-root allocation at $P=Q=2^{64}$. The same fixed root functions support full-key recovery in every security category and reusable precomputation across targets and versions, while a streaming first-distinguished-point construction replaces storage of the signature corpus with certified chain coverage and an identifier-free endpoint index. Its membership-hit law is exact conditional on realized distinct coverage, with separate forecasts for chain construction, tags, fingerprints, and MPHF storage; a Category-I GF(2) design point uses 52 GiB, $2^{52}$ signatures, and target coverage $C=2^{77}$; conditional on that coverage, its success is $0.631940886333$ and its normalized serial forecast is below $2^{94}$. Pinned probes reproduce the fixed roots for every official tag from v2.0.0 through v2.1.1 and a pinned current revision in Categories I, III, and V, and salt-bound, domain-separated root expansion eliminates the collision and reusable-precomputation channels.

Note: Updated with MQOM team acknowledgment and artifact link.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
MQOMpost-quantum signaturesfull-key recoveryMPC-in-the-headmultivariate quadratic cryptography
Contact author(s)
jose @ delgado fyi
History
2026-08-26: revised
2026-07-28: received
See all versions
Short URL
https://ia.cr/2026/1542
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1542,
      author = {José Luis Delgado},
      title = {Signing-Key Recovery from Unsalted Root Expansion and Salt-Binding Repair for {MQOM} v2},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1542},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1542}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.