Full key-recovery attack on SpoC-128

About 6 years old · traced to

Is there a practical full-strength key-recovery attack on the unmodified SpoC-128 authenticated-encryption scheme?

References

Progress summary

Refreshed
Open

No public result has found a practical way to recover the entire secret key of the unchanged SpoC-128 system.

The problem asks whether the unmodified SpoC-128 authenticated-encryption scheme has a practical attack recovering its complete secret key. The retrieved record contains no claimed attack against that exact target.

Known results

  • A 2020 cryptanalysis gives reduced-round attacks, including forgery and message-recovery attacks against 99-round SpoC-64.
  • The same work gives a full-round time-memory-tradeoff key-recovery attack for SpoC-64, not SpoC-128.
  • NIST’s 2020 assessment discusses reduced-round, related-key, and related-nonce analyses, and reports that they do not threaten SpoC-128’s security claims; the full scheme has 1818 rounds.

Current status (as of September 2026): No practical full-strength key-recovery attack on unmodified SpoC-128 is publicly reported; only reduced or modified settings have documented attacks.

  • Claude Mythos 5Anthropicsolved2026-07-01evidence
  • Claude Sonnet 5Anthropicsolved2026-07-01evidence
Sources

Solutions 0

No solutions have been posted yet.