Cryptographer Matthew Green Clarifies "Public Key Crypto Is Broken" Panic: The Real Worry Is Standardized Schemes
After a casual tweet from cryptographer Matthew Green sparked widespread panic that "public-key encryption might be broken," he posted a series of follow-ups clarifying what he actually meant. He made it clear: this does not mean the end of cryptography, is not a descent into Minicrypt, and is absolutely no reason to abandon TLS, send Bitcoin seed phrases in plaintext, or switch to Telegram—encryption is good, keep using it.
Confirmed
- Green stressed the original tweet was written quickly and offhand; he is not worried about public-key cryptography as a whole or the underlying principles of public-key encryption.
- What actually worries him is standardized public-key encryption and some signature schemes, because nearly all of them rest on a handful of hard problems—currently mainly MLWE and ECDLP, supplemented by other lattice-related problems.
- He explained that "losing public-key encryption" really means: new cryptanalysis results will soon emerge that significantly improve attacks on standardized schemes (e.g., 128-bit security levels).
- A milder consequence: some schemes previously considered "good enough" at 128-bit security would no longer meet the bar, possibly offering only 96 or 108 bits of actual security.
- He also suggested that the questions coming from frontier labs might have leaked some hints, and noted that human analysis is not the gold standard.
Why it matters
- This sounds the alarm for re-evaluating standardized cryptographic schemes: the entire public-key ecosystem's single reliance on a few mathematical hard problems means one breakthrough could ripple across widely deployed protocols.
- Green's clarification helps curb overreactions (like abandoning TLS or moving to insecure communication), while reminding the community to focus on diversity in post-quantum and lattice-based schemes.
2026-10-09 ~ 2026-10-09 · 7 related posts
- Episode 1: Cryptographer Matthew Green warns AI could break public-key encryption(2026-10-08, 12 posts)
- Episode 2: AI Math Breakthroughs Raise Concerns Over Public-Key Cryptography(2026-10-08, 2 posts)
- Episode 3: Cryptographer Matthew Green Clarifies "Public Key Crypto Is Broken" Panic: The Real Worry Is Standardized Schemes(2026-10-09, 7 posts)
Primary sources
- Cryptographer Matthew Green: losing public-key crypto means weaker standards, not doom — matthew_d_green ·
- Cryptographer Matthew Green: public-key crypto rests on few hard problems, human analysis isn't gold standard — matthew_d_green ·
- Cryptographer Matthew Green: no imminent cryptanalysis, but frontier labs' questions are telling — matthew_d_green ·
- [source] Cryptographer Matthew Green: no imminent cryptanalysis, but frontier labs' questions are telling — matthew_d_green · 2026-10-09
- Matthew Green clarifies: his worry is standardized public-key encryption's narrow problem base — matthew_d_green · 2026-10-09
- [source] Cryptographer Matthew Green: public-key crypto rests on few hard problems, human analysis isn't gold standard — matthew_d_green · 2026-10-09
- [source] Cryptographer Matthew Green: losing public-key crypto means weaker standards, not doom — matthew_d_green · 2026-10-09
- Green: schemes at 128-bit security may really offer only 96-108 bits — matthew_d_green · 2026-10-09
- Cryptographer: Claude nudged AES attacks by 10 bits, still far from practical — matthew_d_green · 2026-10-09
- Cryptographer Matthew Green: AI (purportedly) improved AES attacks by 10 bits, public-key crypto most at risk — matthew_d_green · 2026-10-09