SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO
AI_SAFETYarxiv_cscr10 Aug 2026

arXiv: Full-Key Recovery and Forgery from One MQOM v2.1 Signature

AI_SAFETY. Sourced from arxiv_cscr, summarised by Matproof.

AI Analysis

What changed and what to do.

A new academic paper, titled "Full-Key Recovery and Forgery from One MQOM v2.1 Signature," has been published on arXiv. The paper demonstrates a practical cryptographic attack against the MQOM v2.1 digital signature scheme, which is a candidate in the ongoing NIST post-quantum cryptography standardization process. The attack allows an adversary to recover the full private signing key and forge signatures using only a single valid signature, completely breaking the scheme's security guarantees. This is a significant finding because MQOM v2.1 was considered a promising multivariate-based alternative to lattice-based post-quantum algorithms.

Organizations affected are primarily those that have already deployed or are piloting MQOM v2.1 for digital signatures, particularly in sectors with long-term data security requirements such as financial services, government, critical infrastructure, and telecommunications. Any compliance team that has mapped MQOM v2.1 into their cryptographic inventory or post-quantum migration roadmap must treat this as a critical vulnerability. The attack does not affect other post-quantum schemes, but it underscores the risk of early adoption of non-finalized algorithms.

Compliance teams should immediately identify any systems or products using MQOM v2.1 and flag them as high-risk. They should pause any new deployments of this scheme and initiate a risk assessment to determine exposure. Next, they should update their cryptographic risk register and inform relevant stakeholders, including IT security and procurement, to avoid future reliance on this algorithm. Finally, they should monitor NIST's official announcements and the paper's peer-review status, and be prepared to transition to alternative post-quantum signatures that have stronger security proofs.

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More AI_SAFETY updates

Latest in AI_SAFETY.

Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.