The cr.yp.to microblog: 2021.06.02 16:50:54

2021.06.02 16:50:54 (1400102632149061633) from Daniel J. Bernstein:

April 2021 posting: https://eprint.iacr.org/2021/570 says it improves lattice attack exponent 0.265 to 0.257. June 2021 posting, dated April 2021: https://web.archive.org/web/20210602144947/https://csrc.nist.gov/CSRC/media/Events/third-pqc-standardization-conference/documents/accepted-papers/kirshanova-lower-bounds-pqc2021.pdf says 0.265 can't be improved for these algorithms. Sounds like at least one of these teams has some explaining to do.