A Second-Order Side-Channel Attack on Masked Kyber768
Part 3 of our series on side-channel attacks against post-quantum cryptography: masking defeats the first-order attack, but <mark>masked Kyber768</mark> still falls to a second-order CPA.
We are the security research team at Ledger, dedicated to protecting your digital assets through cutting-edge security research, vulnerability discovery, and open-source tools.
Technical details of past security issues, their impact, and available patches.
Comprehensive documentation of security objectives and mechanisms.
Open-source security research tools for hardware and software analysis.
Report vulnerabilities and earn rewards for helping secure Ledger products.
Part 3 of our series on side-channel attacks against post-quantum cryptography: masking defeats the first-order attack, but <mark>masked Kyber768</mark> still falls to a second-order CPA.
The Ledger Donjon's journey from AI-assisted development to an AI security harness, and why <mark>offense is no longer only the best defense, but a required security capability.</mark>
Part 2 of our series on side-channel attacks against post-quantum cryptography: we break the <mark>CRYSTALS ML-KEM reference implementation</mark> with a non-profiled deep learning attack — no clone device, no leakage model.
We reward security researchers who help us protect our users. Join our bug bounty program and get recognized in our Hall of Fame.