Improved Collision Attacks on 36- to 39-Step SHA-256

We give two-block differential collision attacks on 36- to 39-step SHA-256 from the standard IV. In the declared cost model their estimated costs are 2^44.6, 2^65.9, 2^83.6 and 2^91.2 reduced-step compression evaluations. The previous best attacks cost 2^57, 2^79.1 and 2^104.3 for 36 to 38 steps, and the characteristic-based estimate for 39 steps was 2^168 (Li et al., ePrint 2026/1120). The 38- and 39-step attacks use a 17 GiB preimage table. The 39-step estimate is below the generic birthday cost 2^128. For each first-block chaining value, we enumerate second-block completions by solving message-expansion equations or matching lists, and we estimate success using modular differences. All costs combine measured rates with stated probabilistic assumptions. The 37- to 39-step attacks remain theoretical. The 36-step attack is practical: it produced 18 new colliding message pairs, all verified independently, where one 36-step pair had been published before. The research, including the attacks, experiments, verification and text, was carried out by AI agents (Anthropic Claude models as researchers, writers and verifiers; OpenAI GPT-6-Astra as reviewer and editor), directed by the author. No human cryptanalyst has yet verified the results independently. The 36-step collisions can be checked with the included scripts. This record contains the paper (PDF) and the complete package: LaTeX source, code, data and reproduction scripts.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23066176
Primary Topic
Cryptographic Implementations and Security
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Improved Collision Attacks on 36- to 39-Step SHA-256

Omer Goldzweig
Zenodo (CERN European Organization for Nuclear Research)
Cryptographic Implementations and Security
preprint

Improved Collision Attacks on 36- to 39-Step SHA-256

Omer Goldzweig
preprint en

Abstract

We give two-block differential collision attacks on 36- to 39-step SHA-256 from the standard IV. In the declared cost model their estimated costs are 2^44.6, 2^65.9, 2^83.6 and 2^91.2 reduced-step compression evaluations. The previous best attacks cost 2^57, 2^79.1 and 2^104.3 for 36 to 38 steps, and the characteristic-based estimate for 39 steps was 2^168 (Li et al., ePrint 2026/1120). The 38- and 39-step attacks use a 17 GiB preimage table. The 39-step estimate is below the generic birthday cost 2^128. For each first-block chaining value, we enumerate second-block completions by solving message-expansion equations or matching lists, and we estimate success using modular differences. All costs combine measured rates with stated probabilistic assumptions. The 37- to 39-step attacks remain theoretical. The 36-step attack is practical: it produced 18 new colliding message pairs, all verified independently, where one 36-step pair had been published before. The research, including the attacks, experiments, verification and text, was carried out by AI agents (Anthropic Claude models as researchers, writers and verifiers; OpenAI GPT-6-Astra as reviewer and editor), directed by the author. No human cryptanalyst has yet verified the results independently. The 36-step collisions can be checked with the included scripts. This record contains the paper (PDF) and the complete package: LaTeX source, code, data and reproduction scripts.

Zenodo (CERN European Organization for Nuclear Research)
Cryptographic Implementations and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Improved Collision Attacks on 36- to 39-Step SHA-256 — Omer Goldzweig · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS