A long bet between Matthew Green and Filippo Valsorda on what will break first: ML-KEM-768 or X25519. You can join! Money goes to charity.
71
19 commits
updated Apr 13, 2026
ML-KEM-768 vs. X25519
This is a public wager between Matthew Green ("Lattice Cryptanalysis side") and Filippo Valsorda ("Quantum Computers side"). Stakes are settled by charitable donation (see Section 7).
It is motivated by views about the security and deployment relevance of the X25519MLKEM768 hybrid handshake. Notwithstanding that motivation, this wager is not about any hybrid handshake, combiner, or protocol composition. The covered constructions are the separate underlying components defined in Section 1.
🗞️ As reported in The Register.
Deadline. December 31, 2040, 23:59:59 UTC.
Stakes.
Back bets.
Anyone can join the bet by choosing a side and stakes for the main and/or secondary wager. If the selected side loses, the back bettor donates the staked amount to the charity chosen by the winner. Back bettors don't select arbiters or charities, but can choose different dollar amounts.
David Adrian: Quantum Computers side / $10,000 on main wager / $2,000 on secondary wager
Joseph Lorenzo Hall: Quantum Computers side / $1,000 on main wager / $500 on secondary wager
Helio Machado: Quantum Computers side / $12,750 on main wager / $950 on secondary wager
sanketh: Lattice Cryptanalysis side / $1,000 on main wager / $200 on secondary wager
Saleem Rashid: Lattice Cryptanalysis side / $2,000 on main wager / $200 on secondary wager
[!TIP] Do you have an opinion and want to put your money where your mouth is? Do you like raising money for charity through abstruse wagers? Submit a PR and add your name above!
ML-KEM-768 means the ML-KEM-768 parameter set as standardized in FIPS 203, used with conforming key generation, encapsulation, and decapsulation on honestly generated inputs.
ML-KEM-512 means the ML-KEM-512 parameter set as standardized in FIPS 203, used with conforming key generation, encapsulation, and decapsulation on honestly generated inputs. It is used only for the moral win in Section 4.
X25519 means X25519 as specified in RFC 7748, used for Diffie–Hellman on honestly generated public keys derived from properly clamped scalars.
The main wager is resolved only by a practical break of one of the covered constructions.
A covered construction is deemed broken if, by the deadline, a practical classical or quantum attack — executed on a real physical machine existing by the deadline — credibly demonstrates any of:
For ML-KEM-768:
For X25519:
The secondary wager captures a substantial, academically recognized downgrade short of a full practical break. Unlike the main wager, it is timeline-based.
ML-KEM-768 is deemed materially downgraded if, by the deadline, either NIST states in substance that ML-KEM-768 no longer meets the 128-bit security level, or a majority of the arbiters concludes — based on peer-reviewed or clearly substantiated public cryptanalysis — that the academic consensus is that ML-KEM-768 no longer meets the 128-bit security level.
If, by the deadline, ML-KEM-768 is no longer considered to meet the 192-bit security level but still meets the 128-bit security level (by the same criteria as 3a), the secondary wager is a push and no donation is made.
If ML-KEM-768 is not deemed to have fallen below the 192-bit security level by the deadline, Filippo wins the secondary wager.
Separate from the main and secondary wagers, Filippo Valsorda buys Matthew Green a reasonable round of drinks if, by the deadline, ML-KEM-512 is no longer considered secure for new deployments.
ML-KEM-512 shall be treated as no longer secure if, by the deadline, either:
This is honorary only and carries no monetary stakes beyond buying drinks.
The following do not count toward any wager:
Arbiters. Three arbiters: one selected by Matthew Green, one by Filippo Valsorda, one jointly selected by both parties. Questions of interpretation and sufficiency of proof are resolved by majority vote.
Evidence. A claimed adverse event may be established by a public result that the arbiters accept, or by a challenge procedure approved by the arbiters.
All monetary wagers are settled by charitable donation. The losing party donates the amount to a U.S. 501(c)(3) organization chosen by the winning party at the time of payout.
Provisional designations:
The winning party may substitute a different 501(c)(3) at the time of payout.
The parties may amend this wager by approving a PR. Adjudications and donations will be announced as edits.
All dollar amounts are in U.S. dollars.
This is a friendly honor-based wager, and not a legally-enforceable agreement.
A long bet between Matthew Green and Filippo Valsorda on what will break first: ML-KEM-768 or X25519. You can join! Money goes to charity.
71
19 commits
updated Apr 13, 2026
ML-KEM-768 vs. X25519
This is a public wager between Matthew Green ("Lattice Cryptanalysis side") and Filippo Valsorda ("Quantum Computers side"). Stakes are settled by charitable donation (see Section 7).
It is motivated by views about the security and deployment relevance of the X25519MLKEM768 hybrid handshake. Notwithstanding that motivation, this wager is not about any hybrid handshake, combiner, or protocol composition. The covered constructions are the separate underlying components defined in Section 1.
🗞️ As reported in The Register.
Deadline. December 31, 2040, 23:59:59 UTC.
Stakes.
Back bets.
Anyone can join the bet by choosing a side and stakes for the main and/or secondary wager. If the selected side loses, the back bettor donates the staked amount to the charity chosen by the winner. Back bettors don't select arbiters or charities, but can choose different dollar amounts.
David Adrian: Quantum Computers side / $10,000 on main wager / $2,000 on secondary wager
Joseph Lorenzo Hall: Quantum Computers side / $1,000 on main wager / $500 on secondary wager
Helio Machado: Quantum Computers side / $12,750 on main wager / $950 on secondary wager
sanketh: Lattice Cryptanalysis side / $1,000 on main wager / $200 on secondary wager
Saleem Rashid: Lattice Cryptanalysis side / $2,000 on main wager / $200 on secondary wager
[!TIP] Do you have an opinion and want to put your money where your mouth is? Do you like raising money for charity through abstruse wagers? Submit a PR and add your name above!
ML-KEM-768 means the ML-KEM-768 parameter set as standardized in FIPS 203, used with conforming key generation, encapsulation, and decapsulation on honestly generated inputs.
ML-KEM-512 means the ML-KEM-512 parameter set as standardized in FIPS 203, used with conforming key generation, encapsulation, and decapsulation on honestly generated inputs. It is used only for the moral win in Section 4.
X25519 means X25519 as specified in RFC 7748, used for Diffie–Hellman on honestly generated public keys derived from properly clamped scalars.
The main wager is resolved only by a practical break of one of the covered constructions.
A covered construction is deemed broken if, by the deadline, a practical classical or quantum attack — executed on a real physical machine existing by the deadline — credibly demonstrates any of:
For ML-KEM-768:
For X25519:
The secondary wager captures a substantial, academically recognized downgrade short of a full practical break. Unlike the main wager, it is timeline-based.
ML-KEM-768 is deemed materially downgraded if, by the deadline, either NIST states in substance that ML-KEM-768 no longer meets the 128-bit security level, or a majority of the arbiters concludes — based on peer-reviewed or clearly substantiated public cryptanalysis — that the academic consensus is that ML-KEM-768 no longer meets the 128-bit security level.
If, by the deadline, ML-KEM-768 is no longer considered to meet the 192-bit security level but still meets the 128-bit security level (by the same criteria as 3a), the secondary wager is a push and no donation is made.
If ML-KEM-768 is not deemed to have fallen below the 192-bit security level by the deadline, Filippo wins the secondary wager.
Separate from the main and secondary wagers, Filippo Valsorda buys Matthew Green a reasonable round of drinks if, by the deadline, ML-KEM-512 is no longer considered secure for new deployments.
ML-KEM-512 shall be treated as no longer secure if, by the deadline, either:
This is honorary only and carries no monetary stakes beyond buying drinks.
The following do not count toward any wager:
Arbiters. Three arbiters: one selected by Matthew Green, one by Filippo Valsorda, one jointly selected by both parties. Questions of interpretation and sufficiency of proof are resolved by majority vote.
Evidence. A claimed adverse event may be established by a public result that the arbiters accept, or by a challenge procedure approved by the arbiters.
All monetary wagers are settled by charitable donation. The losing party donates the amount to a U.S. 501(c)(3) organization chosen by the winning party at the time of payout.
Provisional designations:
The winning party may substitute a different 501(c)(3) at the time of payout.
The parties may amend this wager by approving a PR. Adjudications and donations will be announced as edits.
All dollar amounts are in U.S. dollars.
This is a friendly honor-based wager, and not a legally-enforceable agreement.