PQ-Hammer: End-to-End Key Recovery Attacks on Post-Quantum Cryptography Using Rowhammer
Samy Amer, Yingchen Wang, Hunter Kippen, Thinh Dang, Daniel Genkin, Andrew Kwong, Alexander Nelson, Arkady Yerukhimovich
Abstract
As post-quantum cryptography (PQC) nears standardization and eventual deployment, it is increasingly important to understand the security of the implementations of selected schemes. In this paper, we conduct such an investigation, uncovering concerning findings about many of the finalists of the NIST PQC standardization competition. Specifically, we show Rowhammer-based attacks on the Kyber and BIKE Key Exchange Mechanisms and the Dilithium Digital Signature scheme that enable complete recovery of the secret key with only a moderate amount of effort - no supercomputers, or months of precomputation. Moreover, we experimentally carry out our attacks using a combination of Rowhammer, performance degradation, and memory massaging techniques, showing that our attacks are practically feasible. Our results show that such side-channel based attacks are a critical concern and need to be considered when new cryptographic schemes are standardized, when standard implementations are developed, and when instances are deployed. We conclude with recommendations on implementation techniques that harden cryptographic schemes against Rowhammer attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8a09d783-110a-43e9-acce-234324544994Cited by top-tier papers3
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu et al.S&P 2026 · 8 citations
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 1 citation
- ZK-Hammer: Leaking Secrets from Zero-Knowledge Proofs via RowhammerJunkai Liang, Xin Zhang, Daqi Hu, Qingni Shen et al.DAC 2025
Related papers
- When Frodo Flips: End-to-End Key Recovery on FrodoKEM via RowhammerMichael Fahr, Hunter Kippen, Andrew Kwong, Thinh Dang et al.CCS 2022 · 34 citations
- QuantumHammer: A Practical Hybrid Attack on the LUOV Signature SchemeKoksal Mus, Saad Islam, Berk SunarCCS 2020 · 22 citations
- Breaking Rainbow Takes a Weekend on a LaptopWard BeullensCRYPTO 2022 · 170 citations
- Achilles: A Formal Framework of Leaking Secrets from Signature Schemes via RowhammerJunkai Liang, Zhi Zhang, Xin Zhang, Qingni Shen et al.USENIX Security 2025
- Magic Pot: Cryptanalysis of Full AIM2 in the Standard and Related-/reused-Key Settings Using New Elimination FrameworkAlex Biryukov, Pablo García Fernández, Aleksei UdovenkoEUROCRYPT 2026 · 1 citation
