• FHE Solutions

Edward Teller, Igniting the Atmosphere, and Why Cryptography Works

A new quantum algorithm briefly raised questions about the security foundations behind lattice cryptography and FHE. Niobium CTO David Archer explains what happened, why the claim deserved scrutiny, and what the rapid response says about the cryptography research process.

Edward Teller, Igniting the Atmosphere,  and Why Cryptography Works

Published on

Aug 18, 2026

By David Archer, PhD

In the summer of 1942, at a small gathering of physicists in Berkeley planning what would become the Manhattan Project, Edward Teller raised an unwelcome possibility: might the heat of a fission explosion ignite the nitrogen in the atmosphere and burn the whole sky? The question briefly stopped the room. Hans Bethe and Emil Konopinski took the concern seriously enough to do the physics, and the answer was reassuring: such a reaction could not sustain itself, by a wide margin. The concern was retired, the work continued, and the analysis was checked again before Trinity. Teller did the right thing by raising the concern, just as Bethe and Konopinski did the right thing by running it to ground.

On August 11, 2026, a preliminary draft appeared on the IACR ePrint archive from Daniel Simon at AWS, claiming a polynomial-time quantum algorithm that solves the Dihedral Coset Problem (ePrint:2026/1591). Essentially all deployed cryptography rests on problems believed to require exponential time to solve. A polynomial-time solution means an attacker can break the scheme in practical time no matter how large you make the keys. Through known reductions, the claim would have extended to the Learning With Errors problem, the hardness assumption underneath both the NIST post-quantum standards and every practical fully homomorphic encryption (FHE) scheme, including the ones Niobium’s hardware accelerates.

On August 15, Aparna Gupte, Seyoon Ragavan, and Mark Zhandry formally described a flaw in that algorithm, showing that it does not and cannot solve DCP (ePrint:2026/1693). In particular, they showed that the algorithm cannot recover even a single bit of the secret any better than essentially a random guess. Admirably, the team extended their proof to a broad class of related algorithms.

For modern FHE, this new result shows that lattice cryptography stands, with no change in its security stance. We want to use this post to explain what this episode was, because “someone was wrong on the internet” is the least interesting and least accurate summary available.

Why the claim deserved to be taken seriously

The Dihedral Coset Problem (DCP) is a potential soft spot in the foundations of lattice cryptography. Oded Regev showed long ago that lattice problems reduce to DCP, meaning a fast quantum algorithm for DCP would break lattice-based security. Regev also showed that DCP itself would fall to a quantum computer equipped with an oracle for subset-sum, tantalizingly close to an attack but not one. The problem has sat unresolved for two decades.

The algorithm of ePrint:2026/1591 aimed for a polynomial-time solution, and thus a break in security, by sidestepping the expensive classical post-processing in Regev's earlier approach, discarding seemingly unneeded information along the way. However, the rebuttal paper proves that there’s a flaw in the algorithm, and it isn't fixable: once you discard that information, the secret is unrecoverable too, with anything better than a random guess.

The system worked, and worked fast

The preliminary draft of Simon’s DCP algorithm was posted openly to the venue, The Cryptology Preprint Archive, that exists for exactly this purpose. The people best equipped to evaluate it, several of whom the author had already consulted, dropped what they were doing and evaluated it. Within a few days, the critical step was isolated, tested, and found wanting, and the finding was published just as openly. A similar claim in April 2024 was resolved the same way on a similar timescale.

Very few fields can take a claim that threatens a significant foundation and resolve it, in public, within days. That kind of discipline and cooperation comes from decades of insisting that cryptographic claims come with proofs, and that those proofs be published. Simon’s paper participated in that system exactly as it is meant to be used, and the reviewers’ rebuttal did too. Both deserve credit.

What to take from the week

For users of lattice cryptography and FHE, nothing has changed. But we would gently suggest that the week was a free fire drill. If Simon’s result had held, the questions that mattered would have been: which of your data has a secrecy lifetime long enough to care about future quantum capability, how quickly could your systems change schemes or parameters, and do you actually know where your cryptography is. Those questions have the same answers today as they did during the few days of uncertainty last week. If any of the questions were uncomfortable just now, they are worth acting on while nothing is on fire.

In the early 1940s, Bethe’s calculation did not make the atmosphere safe. The atmosphere was always safe. The calculation is what let everyone know it, and the willingness to take the question seriously is what made the calculation happen. The same is true here: lattice cryptography was not saved this month, because it was not broken this month. But we know its foundations a little better than we did in July, and that knowledge was earned the only way it ever is: by open dialogue and diligence.

To learn more about FHE, hardware acceleration, and Niobium’s encrypted cloud platform, The Fog™, contact us or sign up to join our Developer Partner Program.

David Archer, PhD

Prior to co-founding Niobium, Dr. Archer was a Principal Scientist leading Cryptography & Multiparty Computation for Galois, Inc., with customers including DARPA, the intelligence community, IARPA, and the Department of Homeland Security. Dr. Archer has over 40 years of R&D experience in complex ASICs, system hardware, software architectures, secure computation, and cryptography. Dave holds a PhD in Computer Science, an MS in Electrical Engineering, and a BS in Computer Engineering.

More posts by David