Blog Research
An interpolation attack on 28 of 31 rounds of Poseidon
The first results from our Ethereum Foundation–funded security evaluation of Poseidon: a generalized S-box skipping gadget that linearizes one full round and multiple partial rounds, and yields practical CICO solutions over 28 of 31 rounds.
tl;dr — we present an interpolation attack on 28 out of 31 rounds of Poseidon in practical time, via a novel technique for partial round skipping. Paper: ePrint 2026/1692.
Why Poseidon
Poseidon is an arithmetization-oriented hash function — one designed to be cheap to prove inside a zero-knowledge (ZK) circuit rather than fast to run on a CPU. It is used in critical blockchain infrastructure: most notably, it was adopted by the Ethereum Foundation (EF) as part of Ethereum’s post-quantum roadmap, in LeanVM.
Arithmetization-oriented designs buy their efficiency with large prime fields and very simple algebraic round functions. That is exactly what makes them worth attacking algebraically and why they need adversarial scrutiny that keeps pace with their deployment.
Following a request by the EF, 3MI Labs began a rigorous, adversarial security evaluation of Poseidon under grant number FY26-2457. This post covers the first, but not the last, public work product of this cryptanalysis effort.
The result
The manuscript, “From Round Skipping to S-Box Skipping: Attacking Poseidon’s Partial Layer via Subspace Restriction”, presents a novel linearization approach that restricts the growth of security-critical algebraic properties.
We call the technique GSR, a generalized S-box skipping gadget. It absorbs a single initial full round and t − 2k partial rounds without increasing the polynomial degree of the Poseidon polynomial system, for a state size t and 2k input–output constraints.
By restricting the subspace of solutions that satisfy those constraints, the distinguisher spends input degrees of freedom to linearize the internal state transitions — precisely where the dense algebraic mixing usually happens. A computationally infeasible polynomial system becomes a bounded, low-degree ideal parameterized by k free variables.
Concretely, the gadget gives:
- a probability-1 distinguisher over t − 2k + 1 rounds of Poseidon;
- a basis for interpolation-based attacks — formulated as a reusable cryptanalytic gadget, with the resulting complexities in Table 1 of the paper.
As experimental verification, we include worked solutions for the version of Poseidon previously considered for LeanVM: the parameter setting fixed by the Ethereum Poseidon initiative, using the KoalaBear field with t = 24 and α = 3.
| Problem | Rounds solved |
|---|---|
| CICO-1 | 28 out of 31 |
| CICO-2 | 25 out of 31 |
CICO (“constrained input, constrained output”) is the standard yardstick for arithmetization-oriented permutations: fix part of the input and part of the output, then find a state that connects them. Solving it over a reduced-round version is the usual first step toward an attack on the full primitive.
Crucially, because the subspace restriction is tuned only by t and k, the results apply to the Poseidon structure regardless of the choice of round constants, MDS matrix, S-box exponent, or field size.
Credits
This work was carried out by 3MI Labs researchers Amit Singh Bhati, Sundas Tariq and Tomer Ashur.
The full paper is available at eprint.iacr.org/2026/1692.
Stay tuned for more results.
Please do not hesitate to reach out if you need help evaluating the security of cryptography you rely on or want help understanding how these results affect your implementation of Poseidon.

