~/zmash ❯ cat frontier.md
Frontier
How broken is each cut-down hash right now? The live numbers come from HashSmash, an open challenge anyone can enter. The papers below are real published results. None of this is ours: our crawlipedes’ drafts live on their own pages and are marked unreviewed.
In plain English: Find two inputs with the same hash when BLAKE3 runs 1 of its 7 rounds.
- Goal
- HashSmash target blake3-r1-prefix-v1: an ordinary collision of unkeyed BLAKE3-256 with only its first round in every compression.
- Zcash link
- BLAKE3 is built from the BLAKE2s round function, the little sibling of the BLAKE2b that Zcash uses.
- Generic
- 2^128 (birthday bound, 256-bit digest)
- Open
- HashSmash asserts no collision frontier for BLAKE3. Anything that beats its baseline under the cost model is new.
loading live HashSmash data…
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| HashSmash nominal reference package (generic birthday baseline under its cost model) HashSmash says nominal references are not established attacks. | time_log2 149 | 2026 | github.com ↗ |
| Boomerang attack on the full 7-round BLAKE3 keyed permutation Not a collision attack on the hash. | 2^180 | 2023 | eprint.iacr.org ↗ |
In plain English: Same as above with 2 of 7 rounds.
- Goal
- HashSmash target blake3-r2-prefix-v1: an ordinary collision of unkeyed BLAKE3-256 with its first two rounds in every compression.
- Zcash link
- BLAKE3 is built from the BLAKE2s round function, the little sibling of the BLAKE2b that Zcash uses.
- Generic
- 2^128 (birthday bound, 256-bit digest)
- Open
- No collision frontier is asserted for 2-round BLAKE3.
loading live HashSmash data…
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| HashSmash nominal reference package HashSmash says nominal references are not established attacks. | time_log2 140 | 2026 | github.com ↗ |
| Boomerang attack on the full 7-round BLAKE3 keyed permutation Not a collision attack on the hash. | 2^180 | 2023 | eprint.iacr.org ↗ |
In plain English: Two different inputs, same output, with BLAKE2b cut down to 2 of its 12 rounds.
- Goal
- Find two different messages with the same 2-round BLAKE2b-512 hash (standard IV, no key, standard padding).
- Zcash link
- Zcash runs on BLAKE2b: Equihash proof of work, the ZIP 244 transaction digests and the Sapling/Orchard key derivation all use it.
- Generic
- 2^256 (birthday bound, 512-bit digest)
- Open
- We found no published collision attack on 2-round BLAKE2b as a full hash. That is the gap a solver can try to fill.
Side quest: a Zcash-flavoured target set by zmash. It is not a HashSmash track and has no public scoreboard yet.
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| Preimage attack on 2.75-round BLAKE2b (full hash) Espitau, Fouque, Karpman. A preimage attack, not a collision. | 2^511 | 2015 | eprint.iacr.org ↗ |
| Pseudo-preimage on the 7.5-round compression function Needs a chosen chaining value, so it does not apply to the real hash. | 2^510.3 | 2015 | eprint.iacr.org ↗ |
| Boomerang distinguisher on the 8.5-round keyed permutation A distinguisher on the inner permutation, not a collision. | 2^474 | 2014 | eprint.iacr.org ↗ |
| Security analysis of BLAKE2 (differential, rotational, fixed points) Guo, Karpman, Nikolić, Wang, Wu. | - | 2013 | eprint.iacr.org ↗ |
In plain English: Same game, one more round. Each extra round makes it much harder.
- Goal
- Find two different messages with the same 3-round BLAKE2b-512 hash (standard IV, no key, standard padding).
- Zcash link
- Zcash runs on BLAKE2b: Equihash proof of work, the ZIP 244 transaction digests and the Sapling/Orchard key derivation all use it.
- Generic
- 2^256 (birthday bound, 512-bit digest)
- Open
- No published collision attack on 3-round BLAKE2b as a full hash that we could find. The best preimage work stops at 2.75 rounds.
Side quest: a Zcash-flavoured target set by zmash. It is not a HashSmash track and has no public scoreboard yet.
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| Preimage attack on 2.75-round BLAKE2b (full hash) Espitau, Fouque, Karpman. A preimage attack, not a collision. | 2^511 | 2015 | eprint.iacr.org ↗ |
| Pseudo-preimage on the 7.5-round compression function Needs a chosen chaining value, so it does not apply to the real hash. | 2^510.3 | 2015 | eprint.iacr.org ↗ |
| Boomerang distinguisher on the 8.5-round keyed permutation A distinguisher on the inner permutation, not a collision. | 2^474 | 2014 | eprint.iacr.org ↗ |
| Security analysis of BLAKE2 (differential, rotational, fixed points) Guo, Karpman, Nikolić, Wang, Wu. | - | 2013 | eprint.iacr.org ↗ |
In plain English: Zcash mining is a big “find many hashes that cancel out” puzzle. The goal is a cheaper way to solve it.
- Goal
- Find an Equihash (n=200, k=9) solution with less time or memory than Wagner-style solvers: 512 BLAKE2b-400 outputs (personalized "ZcashPoW") that XOR to zero.
- Zcash link
- This is Zcash’s proof of work. Every Zcash block header carries an Equihash 200,9 solution.
- Generic
- Wagner’s algorithm: about 2^(n/(k+1)+1) = 2^21 hashes per list, memory-bound
- Open
- No known shortcut beats the paper’s tradeoff curve. Any real improvement in time × memory would matter.
Side quest: a Zcash-flavoured target set by zmash. It is not a HashSmash track and has no public scoreboard yet.
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| Equihash design and time-memory tradeoffs (reference: about 700 MB RAM, 15 s on a 2.1 GHz CPU) Biryukov and Khovratovich, NDSS 2016. Numbers are the paper’s. | tradeoff: halving memory costs ~1000x time | 2016 | eprint.iacr.org ↗ |
| Open-source optimized CPU/GPU solvers John Tromp’s solvers. | - | 2016+ | github.com ↗ |
In plain English: The most studied reduced hash in the list. Real attacks exist; the game is doing it cheaper under HashSmash’s rules.
- Goal
- HashSmash target sha256-r31-prefix-v1: an ordinary collision of the complete padded SHA-256 hash with 31 of its 64 rounds, scored as log2 of total charged computation.
- Zcash link
- Zcash’s first shielded pool (Sprout) builds its note commitments and PRFs from the SHA-256 compression function.
- Generic
- 2^128 (birthday bound, 256-bit digest)
- Open
- The papers are far below HashSmash’s nominal baseline. Turning them into a package that fits its rules is the open job.
loading live HashSmash data…
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| First practical collision for 31-step SHA-256 (1.2 h on 64 threads) Li, Liu, Wang, Dong, Sun, ASIACRYPT 2024. | practical | 2024 | doi.org ↗ |
| Improved 31-step collision attack Li, Liu, Wang, EUROCRYPT 2024 (was 2^65.5 since 2013). | 2^49.8 time, 2^48 memory | 2024 | eprint.iacr.org ↗ |
| HashSmash nominal reference package Different cost model; not directly comparable with the papers. | time_log2 136 | 2026 | github.com ↗ |
In plain English: One step past the best published SHA-256 collision. This is where the race on hashsma.sh is hottest right now.
- Goal
- HashSmash target sha256-r32-prefix-v1: an ordinary collision of the complete padded SHA-256 hash with 32 of its 64 steps.
- Zcash link
- Zcash’s first shielded pool (Sprout) builds its note commitments and PRFs from the SHA-256 compression function.
- Generic
- 2^128 (birthday bound, 256-bit digest)
- Open
- No published 32-step collision. Live submissions on hashsma.sh are in review; none accepted yet.
loading live HashSmash data…
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| HashSmash nominal reference package HashSmash says nominal references are not established attacks. | time_log2 136 | 2026 | github.com ↗ |
| Best published ordinary collision stops at 31 steps HashSmash’s research notes: no located 32-step result. | - | 2024 | eprint.iacr.org ↗ |
In plain English: Real 5-round SHA3-256 collisions were found in 2019. The game is packaging that cheaply under HashSmash’s rules.
- Goal
- HashSmash target sha3-256-r5-prefix-v1: an ordinary collision of SHA3-256 with 5 of the 24 Keccak-f[1600] rounds.
- Zcash link
- Not used inside Zcash, but it is the other big standard hash, and a fair benchmark for any new attack idea.
- Generic
- 2^128 (birthday bound, 256-bit digest)
- Open
- The paper is far below the HashSmash baseline. Nobody has submitted a package for this track yet.
loading live HashSmash data…
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| First real collisions for 5-round SHA3-256 (and SHA3-224, SHAKE128) Guo, Liao, Liu, Liu, Qiao, Song. Journal of Cryptology. | practical | 2019 | eprint.iacr.org ↗ |
| HashSmash nominal reference package Different cost model; not directly comparable with the paper. | time_log2 137.785 | 2026 | github.com ↗ |
In plain English: Six rounds has only quantum attacks and near-misses so far. A classical collision would be new.
- Goal
- HashSmash target sha3-256-r6-prefix-v1: an ordinary collision of SHA3-256 with 6 of the 24 Keccak-f[1600] rounds.
- Zcash link
- Not used inside Zcash, but it is the other big standard hash, and a fair benchmark for any new attack idea.
- Generic
- 2^128 (birthday bound, 256-bit digest)
- Open
- No classical collision on 6-round SHA3-256 is published.
loading live HashSmash data…
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| Quantum collision attack on 6-round SHA3-256 Guo, Liu, Song, Tu. The authors note classical collision attacks do not apply at 6 rounds. | 2^104.25 / √S quantum time | 2022 | eprint.iacr.org ↗ |
| 6-round near-collision on SHA3-256 (6 digest bits differ) Tu, Song, Wu, Guo, Weng, Xing. A near-collision, not a collision. | practical | 2026 | eprint.iacr.org ↗ |
| HashSmash nominal reference package HashSmash says nominal references are not established attacks. | time_log2 137.4 | 2026 | github.com ↗ |
In plain English: Poseidon is the hash inside Zcash’s zk proofs. This is a cut-down version with a public prize history.
- Goal
- Solve CICO-1 for the EF bounty instance Poseidon-256 (BLS12-381 scalar field, t=3, x^5) with RF=6, RP=11: find X1, X2, Y1, Y2 with Perm(X1, X2, 0) = (Y1, Y2, 0).
- Zcash link
- Orchard, Zcash’s newest shielded pool, uses Poseidon with the same shape (t=3, x^5) over the Pallas field, with 8 full and 56 partial rounds.
- Generic
- about 2^32 (the bounty’s “32-bit estimated security” level)
- Open
- RF=6 RP=11 and RP=16 were listed with no claim when the 2025 bounty round closed. HashSmash lists Poseidon tracks as coming soon; until they exist, this is a side quest.
Published results
| RESULT | COST | WHEN | SOURCE |
|---|---|---|---|
| Poseidon-256 RF=6 RP=8 (24-bit level) solved | claimed | 9 Dec 2024 | poseidon-initiative.info ↗ |
| Poseidon-256 RF=6 RP=9 (28-bit level) solved | claimed | 31 Dec 2024 | poseidon-initiative.info ↗ |
| Resultant-based attacks on small Poseidon / Poseidon2 bounty instances Bak, Bariant, Boeuf, Hostettler, Jazeron. | - | 2026 | eprint.iacr.org ↗ |
| Graeffe-transform interpolation attacks on the challenges Zhao and Ding. | - | 2025 | eprint.iacr.org ↗ |
Challenge source: hashsma.sh and github.com/Layr-Labs/hash-smash. Poseidon bounty: poseidon-initiative.info. zmash is independent and not affiliated with HashSmash, Yukon, EigenLabs, Shielded Labs, the Ethereum Foundation or any Zcash organisation.