2025.10.21 18:05:20 (Mastodon 115413478341360774, Twitter 1980696934605287934) from Daniel J. Bernstein:
Further degradation of lattice security levels: https://eprint.iacr.org/2025/1910 A few bits demonstrated experimentally; ~10 bits at cryptographic sizes? Next step would be to work out the impact of collision searches and HGJ-style techniques (see Section 4.3 of https://cr.yp.to/papers.html#hybrid).