Eigen Labs and Shielded Labs have opened HashSmash, a public competition that asks researchers and AI agents to search for practical weaknesses in four cryptographic hash functions used across blockchain systems and internet infrastructure: SHA-256, SHA-3, BLAKE3 and Poseidon. The Oct. 5 launch puts AI-assisted cryptanalysis under public scrutiny, with submissions posted on Eigen Labs’ Yukon research platform and reviewed by specialist cryptographers.
The contest is built around whether increasingly capable AI systems can discover attack methods against cryptographic primitives that have long been treated as foundational security tools. Participants must explain precisely what a proposed method would break, how it works, and the computing resources required to execute it.
HashSmash does not ask competitors merely to generate theoretical concerns. The organizers want reproducible attacks or measurable improvements in cryptanalysis, the field devoted to testing and breaking cryptographic systems. A successful result could range from a new way to find collisions — two distinct inputs producing the same hash — to a reduced-cost technique for attacking a function’s security assumptions, depending on the challenge specifications.
Four hash functions under examination
Hash functions turn data into fixed-length digital fingerprints. Their role is pervasive: they help verify files, secure software, connect blocks in blockchains, support digital signatures, and underpin many zero-knowledge proof systems. Security depends on the expectation that attackers cannot feasibly reverse a hash, find a second input with the same output, or generate collisions at a cost low enough to be useful.
SHA-256 is the most recognizable target in the group because it is embedded in Bitcoin’s proof-of-work system and appears in numerous security protocols. SHA-3 is a newer standard developed after the SHA-3 competition run by the U.S. National Institute of Standards and Technology. BLAKE3 is a high-speed hash function used in software and data-integrity applications. Poseidon was designed for zero-knowledge systems, where conventional hashes can be costly to compute inside cryptographic proofs.
Putting these functions in the same competition gives researchers a way to compare how AI performs against designs created for different trade-offs. SHA-256 and SHA-3 were built as general-purpose cryptographic standards, while Poseidon was optimized for proof systems used by privacy and scaling technologies.
The organizers said entries may use SAT solvers, formal methods, automated differential searches, or combinations of those approaches. SAT solvers are programs that search for solutions to logical constraints, while differential cryptanalysis tracks how changes to an input affect a cryptographic function’s output. Such methods have been part of conventional cryptanalysis for years; HashSmash is testing whether AI agents can make them more effective, faster, or more creative.
Public review is central to the format
Submissions will first go through an AI verifier before assessment by a committee of expert cryptographers, according to the competition description. Results will remain public on Yukon, allowing other participants to inspect, challenge, extend, or improve previous work.
That open format makes the event more than a private security exercise. A claimed attack must withstand examination from researchers who can reproduce its assumptions and calculations. Cryptographic claims often look stronger than they are until independent reviewers test whether they apply to the full function, a reduced-round version, or only an unrealistic computing environment.
Eigen Labs describes Yukon as an open research platform for humans and AI agents to work on scientific and technical problems with publicly tracked submissions and outcomes. The company said earlier Yukon challenges included ECDSA.fail, which it said surpassed a Google Quantum AI benchmark by more than 60%, as well as optimization efforts called Lighter.fast and MLX.fast.
Eigen Labs and the Ethereum Foundation have also used Yukon for sig.golf, a challenge focused on post-quantum cryptographic security for Ethereum. HashSmash extends that model from signature systems to hash functions, which often sit lower in the technical stack and can affect many applications at once.
Zcash research effort links AI and quantum threats
Shielded Labs connected HashSmash to Epoch, its research and engineering project intended to prepare Zcash for threats including quantum computers, advanced AI systems, sophisticated hacking groups, and state-backed adversaries.
Zcash uses zero-knowledge cryptography to enable transactions with privacy protections. Those systems rely on several mathematical components, including hashes and proof-friendly cryptographic constructions. Testing the resilience of primitives such as Poseidon therefore has direct relevance for projects building privacy-preserving applications and zero-knowledge infrastructure.
The contest also reflects a practical concern for protocol developers: AI’s security impact may emerge first through improvements to narrow technical tasks rather than a single dramatic breakthrough. AI agents that help researchers automate code review have already uncovered software vulnerabilities. HashSmash asks whether similar systems can contribute useful advances in a field where the targets are mathematical constructions rather than ordinary application code.
A discovery in the competition would need careful interpretation. Weaknesses against reduced-round versions of a hash function, for example, can provide valuable research insight without creating an immediate threat to the full version deployed in production. Likewise, an attack requiring extraordinary computing power may not be economically practical. HashSmash’s requirement that entrants disclose resource needs is intended to distinguish academic progress from attacks that could alter real-world security assumptions.
The results may give blockchain developers and cryptographers an early view of which AI-assisted methods are productive, where existing hash designs remain resistant, and which areas deserve additional review. HashSmash is available through Yukon.org, with the organizers planning to make the competition’s findings available to researchers and cryptographers.
Explore how traders harness AI beyond cryptanalysis with Toobit’s AI copy trading guide for automated crypto strategies.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
