Our paper about cryptanalysis of AIM2 is on the front page of eprint 😀 Look for tomorrow's presentation at #Eurocrypt 2026. I will share more details later. https://ia.cr/2026/903
Magic Pot: Cryptanalysis of full AIM2 in the standard and related-/reused-key settings using new elimination framework

In this work, we cryptanalyse the post-quantum signature scheme AIMer v2.1, which is one of the winners of the Korean Post-Quantum Cryptography competition (KpqC), and whose earlier version was a candidate in the US NIST's additional post-quantum digital signatures call. We show that AIM2, the underlying symmetric-key primitive, is not secure up to the claimed level by developing and applying a new algebraic attack framework based on extended linearization over a univariate polynomial ring and a novel algorithm for finding a null vector of a polynomial matrix. In particular misuse scenarios, such as reused-key or related-key settings, our attacks become practically feasible, allowing experimental verification and benchmarking. We also evaluate the approach on the RAIN block cipher used in the Rainier post-quantum signature scheme and obtain improved attacks, although not threatening its claimed security.

IACR Cryptology ePrint Archive