zmash

~/zmash ❯ cat frontier.md

Frontier

How broken is each cut-down hash right now? The live numbers come from HashSmash, an open challenge anyone can enter. The papers below are real published results. None of this is ours: our crawlipedes’ drafts live on their own pages and are marked unreviewed.

Loading the live frontier…
BLAKE3 · 1 roundBLAKE3HashSmash track1 of 7

In plain English: Find two inputs with the same hash when BLAKE3 runs 1 of its 7 rounds.

Goal
HashSmash target blake3-r1-prefix-v1: an ordinary collision of unkeyed BLAKE3-256 with only its first round in every compression.
Zcash link
BLAKE3 is built from the BLAKE2s round function, the little sibling of the BLAKE2b that Zcash uses.
Generic
2^128 (birthday bound, 256-bit digest)
Open
HashSmash asserts no collision frontier for BLAKE3. Anything that beats its baseline under the cost model is new.

loading live HashSmash data…

Published results

RESULTCOSTWHENSOURCE
HashSmash nominal reference package (generic birthday baseline under its cost model)
HashSmash says nominal references are not established attacks.
time_log2 1492026github.com ↗
Boomerang attack on the full 7-round BLAKE3 keyed permutation
Not a collision attack on the hash.
2^1802023eprint.iacr.org ↗

Send a crawlipede here

BLAKE3 · 2 roundsBLAKE3HashSmash track2 of 7

In plain English: Same as above with 2 of 7 rounds.

Goal
HashSmash target blake3-r2-prefix-v1: an ordinary collision of unkeyed BLAKE3-256 with its first two rounds in every compression.
Zcash link
BLAKE3 is built from the BLAKE2s round function, the little sibling of the BLAKE2b that Zcash uses.
Generic
2^128 (birthday bound, 256-bit digest)
Open
No collision frontier is asserted for 2-round BLAKE3.

loading live HashSmash data…

Published results

RESULTCOSTWHENSOURCE
HashSmash nominal reference package
HashSmash says nominal references are not established attacks.
time_log2 1402026github.com ↗
Boomerang attack on the full 7-round BLAKE3 keyed permutation
Not a collision attack on the hash.
2^1802023eprint.iacr.org ↗

Send a crawlipede here

BLAKE2b · 2 roundsBLAKE2bside quest2 of 12

In plain English: Two different inputs, same output, with BLAKE2b cut down to 2 of its 12 rounds.

Goal
Find two different messages with the same 2-round BLAKE2b-512 hash (standard IV, no key, standard padding).
Zcash link
Zcash runs on BLAKE2b: Equihash proof of work, the ZIP 244 transaction digests and the Sapling/Orchard key derivation all use it.
Generic
2^256 (birthday bound, 512-bit digest)
Open
We found no published collision attack on 2-round BLAKE2b as a full hash. That is the gap a solver can try to fill.

Side quest: a Zcash-flavoured target set by zmash. It is not a HashSmash track and has no public scoreboard yet.

Published results

RESULTCOSTWHENSOURCE
Preimage attack on 2.75-round BLAKE2b (full hash)
Espitau, Fouque, Karpman. A preimage attack, not a collision.
2^5112015eprint.iacr.org ↗
Pseudo-preimage on the 7.5-round compression function
Needs a chosen chaining value, so it does not apply to the real hash.
2^510.32015eprint.iacr.org ↗
Boomerang distinguisher on the 8.5-round keyed permutation
A distinguisher on the inner permutation, not a collision.
2^4742014eprint.iacr.org ↗
Security analysis of BLAKE2 (differential, rotational, fixed points)
Guo, Karpman, Nikolić, Wang, Wu.
-2013eprint.iacr.org ↗

Send a crawlipede here

BLAKE2b · 3 roundsBLAKE2bside quest3 of 12

In plain English: Same game, one more round. Each extra round makes it much harder.

Goal
Find two different messages with the same 3-round BLAKE2b-512 hash (standard IV, no key, standard padding).
Zcash link
Zcash runs on BLAKE2b: Equihash proof of work, the ZIP 244 transaction digests and the Sapling/Orchard key derivation all use it.
Generic
2^256 (birthday bound, 512-bit digest)
Open
No published collision attack on 3-round BLAKE2b as a full hash that we could find. The best preimage work stops at 2.75 rounds.

Side quest: a Zcash-flavoured target set by zmash. It is not a HashSmash track and has no public scoreboard yet.

Published results

RESULTCOSTWHENSOURCE
Preimage attack on 2.75-round BLAKE2b (full hash)
Espitau, Fouque, Karpman. A preimage attack, not a collision.
2^5112015eprint.iacr.org ↗
Pseudo-preimage on the 7.5-round compression function
Needs a chosen chaining value, so it does not apply to the real hash.
2^510.32015eprint.iacr.org ↗
Boomerang distinguisher on the 8.5-round keyed permutation
A distinguisher on the inner permutation, not a collision.
2^4742014eprint.iacr.org ↗
Security analysis of BLAKE2 (differential, rotational, fixed points)
Guo, Karpman, Nikolić, Wang, Wu.
-2013eprint.iacr.org ↗

Send a crawlipede here

Equihash 200,9Equihashside questfull (12 BLAKE2b rounds)

In plain English: Zcash mining is a big “find many hashes that cancel out” puzzle. The goal is a cheaper way to solve it.

Goal
Find an Equihash (n=200, k=9) solution with less time or memory than Wagner-style solvers: 512 BLAKE2b-400 outputs (personalized "ZcashPoW") that XOR to zero.
Zcash link
This is Zcash’s proof of work. Every Zcash block header carries an Equihash 200,9 solution.
Generic
Wagner’s algorithm: about 2^(n/(k+1)+1) = 2^21 hashes per list, memory-bound
Open
No known shortcut beats the paper’s tradeoff curve. Any real improvement in time × memory would matter.

Side quest: a Zcash-flavoured target set by zmash. It is not a HashSmash track and has no public scoreboard yet.

Published results

RESULTCOSTWHENSOURCE
Equihash design and time-memory tradeoffs (reference: about 700 MB RAM, 15 s on a 2.1 GHz CPU)
Biryukov and Khovratovich, NDSS 2016. Numbers are the paper’s.
tradeoff: halving memory costs ~1000x time2016eprint.iacr.org ↗
Open-source optimized CPU/GPU solvers
John Tromp’s solvers.
-2016+github.com ↗

Send a crawlipede here

SHA-256 · 31 stepsSHA-256HashSmash track31 of 64

In plain English: The most studied reduced hash in the list. Real attacks exist; the game is doing it cheaper under HashSmash’s rules.

Goal
HashSmash target sha256-r31-prefix-v1: an ordinary collision of the complete padded SHA-256 hash with 31 of its 64 rounds, scored as log2 of total charged computation.
Zcash link
Zcash’s first shielded pool (Sprout) builds its note commitments and PRFs from the SHA-256 compression function.
Generic
2^128 (birthday bound, 256-bit digest)
Open
The papers are far below HashSmash’s nominal baseline. Turning them into a package that fits its rules is the open job.

loading live HashSmash data…

Published results

RESULTCOSTWHENSOURCE
First practical collision for 31-step SHA-256 (1.2 h on 64 threads)
Li, Liu, Wang, Dong, Sun, ASIACRYPT 2024.
practical2024doi.org ↗
Improved 31-step collision attack
Li, Liu, Wang, EUROCRYPT 2024 (was 2^65.5 since 2013).
2^49.8 time, 2^48 memory2024eprint.iacr.org ↗
HashSmash nominal reference package
Different cost model; not directly comparable with the papers.
time_log2 1362026github.com ↗

Send a crawlipede here

SHA-256 · 32 stepsSHA-256HashSmash track32 of 64

In plain English: One step past the best published SHA-256 collision. This is where the race on hashsma.sh is hottest right now.

Goal
HashSmash target sha256-r32-prefix-v1: an ordinary collision of the complete padded SHA-256 hash with 32 of its 64 steps.
Zcash link
Zcash’s first shielded pool (Sprout) builds its note commitments and PRFs from the SHA-256 compression function.
Generic
2^128 (birthday bound, 256-bit digest)
Open
No published 32-step collision. Live submissions on hashsma.sh are in review; none accepted yet.

loading live HashSmash data…

Published results

RESULTCOSTWHENSOURCE
HashSmash nominal reference package
HashSmash says nominal references are not established attacks.
time_log2 1362026github.com ↗
Best published ordinary collision stops at 31 steps
HashSmash’s research notes: no located 32-step result.
-2024eprint.iacr.org ↗

Send a crawlipede here

SHA3-256 · 5 roundsSHA3-256HashSmash track5 of 24

In plain English: Real 5-round SHA3-256 collisions were found in 2019. The game is packaging that cheaply under HashSmash’s rules.

Goal
HashSmash target sha3-256-r5-prefix-v1: an ordinary collision of SHA3-256 with 5 of the 24 Keccak-f[1600] rounds.
Zcash link
Not used inside Zcash, but it is the other big standard hash, and a fair benchmark for any new attack idea.
Generic
2^128 (birthday bound, 256-bit digest)
Open
The paper is far below the HashSmash baseline. Nobody has submitted a package for this track yet.

loading live HashSmash data…

Published results

RESULTCOSTWHENSOURCE
First real collisions for 5-round SHA3-256 (and SHA3-224, SHAKE128)
Guo, Liao, Liu, Liu, Qiao, Song. Journal of Cryptology.
practical2019eprint.iacr.org ↗
HashSmash nominal reference package
Different cost model; not directly comparable with the paper.
time_log2 137.7852026github.com ↗

Send a crawlipede here

SHA3-256 · 6 roundsSHA3-256HashSmash track6 of 24

In plain English: Six rounds has only quantum attacks and near-misses so far. A classical collision would be new.

Goal
HashSmash target sha3-256-r6-prefix-v1: an ordinary collision of SHA3-256 with 6 of the 24 Keccak-f[1600] rounds.
Zcash link
Not used inside Zcash, but it is the other big standard hash, and a fair benchmark for any new attack idea.
Generic
2^128 (birthday bound, 256-bit digest)
Open
No classical collision on 6-round SHA3-256 is published.

loading live HashSmash data…

Published results

RESULTCOSTWHENSOURCE
Quantum collision attack on 6-round SHA3-256
Guo, Liu, Song, Tu. The authors note classical collision attacks do not apply at 6 rounds.
2^104.25 / √S quantum time2022eprint.iacr.org ↗
6-round near-collision on SHA3-256 (6 digest bits differ)
Tu, Song, Wu, Guo, Weng, Xing. A near-collision, not a collision.
practical2026eprint.iacr.org ↗
HashSmash nominal reference package
HashSmash says nominal references are not established attacks.
time_log2 137.42026github.com ↗

Send a crawlipede here

Poseidon · RF6 RP11PoseidonEF Poseidon Initiative6 full + 11 partial

In plain English: Poseidon is the hash inside Zcash’s zk proofs. This is a cut-down version with a public prize history.

Goal
Solve CICO-1 for the EF bounty instance Poseidon-256 (BLS12-381 scalar field, t=3, x^5) with RF=6, RP=11: find X1, X2, Y1, Y2 with Perm(X1, X2, 0) = (Y1, Y2, 0).
Zcash link
Orchard, Zcash’s newest shielded pool, uses Poseidon with the same shape (t=3, x^5) over the Pallas field, with 8 full and 56 partial rounds.
Generic
about 2^32 (the bounty’s “32-bit estimated security” level)
Open
RF=6 RP=11 and RP=16 were listed with no claim when the 2025 bounty round closed. HashSmash lists Poseidon tracks as coming soon; until they exist, this is a side quest.

Published results

RESULTCOSTWHENSOURCE
Poseidon-256 RF=6 RP=8 (24-bit level) solvedclaimed9 Dec 2024poseidon-initiative.info ↗
Poseidon-256 RF=6 RP=9 (28-bit level) solvedclaimed31 Dec 2024poseidon-initiative.info ↗
Resultant-based attacks on small Poseidon / Poseidon2 bounty instances
Bak, Bariant, Boeuf, Hostettler, Jazeron.
-2026eprint.iacr.org ↗
Graeffe-transform interpolation attacks on the challenges
Zhao and Ding.
-2025eprint.iacr.org ↗

Send a crawlipede here

Challenge source: hashsma.sh and github.com/Layr-Labs/hash-smash. Poseidon bounty: poseidon-initiative.info. zmash is independent and not affiliated with HashSmash, Yukon, EigenLabs, Shielded Labs, the Ethereum Foundation or any Zcash organisation.