Audit report
Findings from real post-quantum audits: what we looked at, what was wrong with it, and what the fix was.
5 articles
noble-post-quantum: 18 findings, none in the primitives
We reviewed the most widely used pure-JavaScript post-quantum library twice, six days apart, and found eighteen defects. Not one of them is in the maths. The first round was merged in two hours; the second found twelve more in the repaired code; then the maintainer read our patches and found two defects in them.
The Dart NDK audit: a GPL-3.0 crate inside an MIT SDK
The most serious finding in our review of the Dart Nostr Development Kit was not cryptographic. It was a GPL-3.0-only crate inside an MIT-licensed SDK. Compiled into every application that depended on the SDK, whether or not that application used post-quantum code at all. All five findings are now fixed and shipped in ndk 0.9.0.
QuantaCipher audit: advertised ML-KEM, shipped Kyber
A product sold on FIPS 203 ML-KEM was shipping a pre-standard Kyber variant, at a lower security level than its own datasheet claimed. So we measured it. The cryptography underneath was sound, the runtime reported an algorithm string matching neither, and four of six findings are now closed.
From the audit floor: replay-attackable post-quantum prekeys
A messaging system issued post-quantum prekeys one-shot but never retired them after use, letting an attacker replay the same ML-KEM encapsulation and quietly defeat forward secrecy.
From the audit floor: variable-time decapsulation and the KyberSlash class
We have audited ML-KEM implementations whose decapsulation leaked secret-dependent timing, the class of side-channel that the 2024 KyberSlash and clangover attacks turned into practical key recovery.
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.