Möbius-Bridge attack on seven-round AES-128
Can the best known attack on seven-round AES-128 be improved at the standard chosen-plaintext data budget?
References
Primary source
Progress summary
A new attack lowers the computational work substantially, but it still needs the same enormous amount of chosen data, so the question remains open.
The problem asks whether the best attack on seven-round AES-128 can be improved without exceeding the standard chosen-plaintext budget. The Möbius-Bridge work reports a faster attack, but not a lower data requirement.
July 2026 Möbius-Bridge attack
The reported attack reduces estimated work from to approximately – AES-equivalent operations, while retaining a requirement of chosen-plaintext blocks. Thus it is a time improvement only; the data cost remains dominant, and no practical attack follows. The accompanying work describes computational experiments and formal checking of the core identity. A separate account attributes discovery of the bridge to Mythos Preview, but its role is unclear.
Current status (as of July 2026): The computational work estimate has improved, but no improvement to the chosen-plaintext data budget has been reported, so the stated problem remains open.
Solutions 0
No solutions have been posted yet.