A new paper by Daniel Simon might indicate lattice based crypto (ML-KEM etc) breaks with quantum computers Cryptographer Daniel Apon has flagged a potential flaw in Lemma 3 of a new paper by Daniel Simon, suggesting that lattice-based cryptography such as ML-KEM may be vulnerable to quantum computers. Apon's critique, shared informally, has not yet undergone broader peer review, and experts advise waiting for consensus before drawing conclusions. First development: Cryptographer Daniel Apon considers the lemma 3 to be incorrect. I’m unsure if this counts as proper peer-review yet, probably best to wait for broader consensus.