Stream Cipher
Snow 2
A modern Rust reimplementation of SNOW with AEAD support, Argon2id-derived keys, and steganographic output options.
Post-Quantum
Quantum Vault KpqC
Threshold short-secret encryption using secret sharing and Korean post-quantum cryptography, compiled to WASM for direct browser use.
Stateless Passwords
Phantom Vault
Derive any password from a master passphrase using HMAC-DRBG. Nothing stored, nothing synced, nothing left behind to breach.
Backdoored RNG
Corrupted Oracle
A live Dual_EC_DRBG backdoor demo showing state recovery and future-output prediction while standard statistical tests still appear clean.
CSPRNG
DRBG Arena
HMAC_DRBG, CTR_DRBG, and Hash_DRBG with state visualizers, seeding, reseeding, and live NIST SP 800-22 statistical tests. The correct-case companion to Corrupted Oracle.
Quantum Key Distribution
BB84
Quantum key distribution with photon polarization, basis sifting, QBER eavesdropper detection, and privacy amplification before AES-256-GCM message encryption.
Post-Quantum Cryptanalysis
Shor
Modular period finding with QFT and continued fractions to recover integer factors, showing why RSA, ECC, and Diffie-Hellman must migrate to post-quantum alternatives.
Post-Quantum Cryptanalysis
Grover
Amplitude amplification and oracle phase kickback for symmetric-key search, with live probability oscillation and concrete key-size impact (AES-128 to AES-256).
Cryptanalysis
Model Breach
A HiAE threat-model case study showing candidate enumeration, MITM state recovery, and guess-and-determine attacks when assumptions drift from deployment reality.
Asymmetric Encryption
Iron Letter
ECIES P-256 and RSA-OAEP compared side by side with live timing, key-size tradeoffs, and a simple sealed-letter mental model.
Deniable Encryption
Shadow Vault
One container, two passphrases, two messages. A practical demonstration of plausible deniability, forensic ambiguity, and browser-first UX around serious primitives.
Zero-Knowledge Proofs
ZK Proof Lab
Six exhibits from Ali Baba cave to zk-SNARK intuition, with real Schnorr arithmetic, commitments, and replayable transcripts instead of vague metaphors.
Zero-Knowledge Proofs
STARK Tower
AIR constraints, FRI polynomial commitments, and end-to-end Fibonacci proof. No trusted setup, post-quantum secure. The protocol behind StarkNet, StarkEx, and Risc Zero.
Zero-Knowledge Proofs
SNARK Arena
Groth16 vs PLONK — trusted setup ceremonies, proof size comparison, the toxic waste problem, and production deployments in Zcash, Polygon zkEVM, WorldID, and zkLogin.
Homomorphic Encryption
Blind Oracle
A server computes on encrypted values without seeing the plaintext. A concise, live introduction to FHE using TFHE-rs.
⚡ The one exceptionThis is the lab's single demo with a live backend — a Rust/TFHE-rs server adds your two encrypted numbers homomorphically and still mathematically cannot read them.
Homomorphic Encryption
CKKS Lab
Approximate FHE for encrypted floating-point arithmetic, homomorphic neural network inference, rescaling, and the complete FHE trilogy (TFHE + BGV/BFV + CKKS).
Homomorphic Encryption
FHE Arena
BGV/BFV integer FHE — homomorphic addition and multiplication, live noise budget visualizer, relinearization, SIMD batching, and real-world deployments in private genomics and encrypted databases.
Encrypted Morse
Dad Mode Morse
AES-GCM encrypted messaging delivered as Morse code with audio playback and browser decoding. Intentionally playful, still grounded in real primitives.
Library Privacy
Patron Shield
Information-theoretic private information retrieval applied to catalog privacy. A direct bridge from library ethics to concrete mathematical guarantees.
Verifiable Secret Sharing
VSS Gate
Feldman VSS and Pedersen VSS — verifiable secret sharing with live cheating dealer detection, commitment verification, and the layer beneath FROST and threshold wallets.
Secure MPC
Garbled Gate
Yao’s Garbled Circuits — gate-by-gate garbling, oblivious transfer for input wires, and the Millionaire’s Problem solved end-to-end. The foundational two-party MPC protocol.
Secure MPC
Silent Tally
Five hospitals compute a combined enrollment total without revealing any individual counts, demonstrating additive-homomorphic MPC in the browser.
Threshold Signatures
FROST Threshold
A browser-based FROST (RFC 9591) walkthrough where any qualified signer subset can produce one standard Ed25519 signature without key reassembly.
Post-Quantum Signatures
Dilithium Seal
CRYSTALS-Dilithium (ML-DSA) digital signatures in the browser. Generate lattice-based key pairs, sign documents, and verify — all post-quantum safe.
Forward-Secret Messaging
Ratchet Wire
A live walkthrough of the Double Ratchet protocol powering Signal-style messaging, with per-message key derivation and forward secrecy guarantees.
Post-Quantum KEM
Kyber Vault
CRYSTALS-Kyber (ML-KEM) key encapsulation in the browser. Encapsulate, decapsulate, and compare lattice-based key exchange against classical ECDH.
Block Cipher
Iron Serpent
The Serpent block cipher — AES finalist with a deeper security margin. Avalanche analysis, a security-margin (round-count) view, and side-by-side AES comparison.
Block Cipher
World Ciphers
Camellia (Japan), ARIA (South Korea), SM4 (China), and Kuznyechik (Russia) side by side with AES. Encrypt/decrypt playgrounds, S-box analysis, and geopolitical compliance context.
Secret Sharing
Shamir Gate
Split a secret into shares using Shamir's Secret Sharing and reconstruct with any qualified threshold subset. Polynomial interpolation made tangible.
Historical Cipher
Dead Sea Cipher
Substitution and polyalphabetic ciphers from Atbash to Vigenère, through to modern AES-256-GCM. Encode, decode, and explore classical cryptanalysis.
Hash-Based Signatures
SPHINCS+ Ledger
Stateless hash-based signatures (SLH-DSA) in the browser. A post-quantum signing scheme that relies only on the security of hash functions.
Differential Cryptanalysis
Biham Lens
A live differential cryptanalysis attack on a toy SPN cipher — the technique co-invented by Biham and Shamir that broke reduced-round DES. DDT visualization and last-round key recovery.
Hybrid Key Exchange
Hybrid Wire
X25519 + ML-KEM-768 hybrid post-quantum key exchange as deployed in Chrome 124+ and Cloudflare. Six-step handshake visualization and encrypted chat.
Hash Functions
Babel Hash
SHA-256, SHA3-256, and BLAKE3 side by side with live avalanche visualization, length extension attack demo, and HMAC defense.
Block Cipher Modes
AES Modes
ECB, CBC, CTR, GCM, and CCM with live padding oracle attack. Real WebCrypto operations, ECB penguin visualization, and authenticated encryption comparison.
Public-Key Cryptography
Educational RSA
Step-by-step RSA on real small numbers — key generation, encryption, decryption, and signatures — then watch a weak key get factored in milliseconds while a 2048-bit key holds. Real BigInt math, no backend.
Public-Key Cryptography
RSA Forge
Textbook RSA, OAEP, PSS signatures, and live attacks including small exponent and Bleichenbacher PKCS#1 v1.5 padding oracle. Real WebCrypto operations.
Elliptic Curves
Curve Lens
Point addition, scalar multiplication, and live ECDH across P-256, Curve25519, and secp256k1. Real field arithmetic visualized step by step.
Elliptic Curves
Point Arithmetic
Drag P and Q to see the chord-and-tangent group law, flip ℝ↔𝔽ₚ to run the identical exact arithmetic, then step double-and-add and feel why the ECDLP is hard.
Asynchronous Key Agreement
X3DH Wire
The asynchronous handshake behind Signal. Real X25519 arithmetic, four DH operations, and HKDF-SHA-256 key derivation — no backends, no simulated math.
Noise Protocol Framework
Noise Pipe
NN, XX, IK, and IKpsk2 handshake patterns with real X25519 arithmetic, live transport encryption, and a WireGuard deep dive.
Message Authentication
MAC Race
HMAC, CMAC, Poly1305, and GHASH compared with live length extension attack, timing attack, and nonce reuse demonstrations. Real WebCrypto operations.
Key Derivation
KDF Chain
HKDF, PBKDF2, scrypt, and Argon2id compared side by side with live parameter tuning, real timing measurements, and a KDF decision tree.
Format-Preserving Encryption
Format Ward
FF1 and FF3-1 live tokenization of credit cards, SSNs, and phone numbers. Real AES-256 Feistel rounds per NIST SP 800-38G.
CBC Padding Oracle
Padding Oracle
Full Vaudenay 2002 chosen-ciphertext attack with real AES-CBC, byte-by-byte plaintext recovery, and coverage of ASP.NET, Lucky Thirteen, and POODLE.
Timing Side-Channel
Timing Oracle
String comparison leakage, HMAC verification timing, RSA private key bit leakage, and cache-timing attacks with real performance.now() measurements.
Post-Quantum KEM
McEliece Gate
The oldest post-quantum KEM (1978). Binary Goppa codes, visceral 261KB public key visualization, and four-way comparison against ML-KEM, BIKE, and HQC.
Post-Quantum KEM
Frodo Vault
Conservative post-quantum KEM using plain LWE with no ring structure. LWE from first principles, error distribution, and side-by-side comparison against ML-KEM.
Code-Based KEM
BIKE Vault
Code-based post-quantum KEM using QC-MDPC codes, Black-Gray-Flip decoding, and side-by-side comparison against ML-KEM. NIST Round 4 alternate candidate.
Code-Based KEM
HQC Vault
Hamming Quasi-Cyclic post-quantum KEM with Reed-Muller/Reed-Solomon decoding, and three-way comparison against BIKE and ML-KEM.
Post-Quantum Signatures
Falcon Seal
Compact NTRU lattice signatures with Fast Fourier Sampling, side-by-side comparison against ML-DSA and SLH-DSA, and implementation security warnings.
Stream Cipher
ChaCha20 Stream
Quarter-round stepper, keystream visualizer, nonce reuse attack demo, and encrypt/decrypt playground. ARX design, no AES-NI required.
Digital Signatures
Ed25519 Forge
Keypair generation, signing, and signature verification — deterministic nonces, tamper detection, the ZIP215 cofactor pitfall, and 64-byte compact signatures.
Hash Construction
Hash Zoo
SHA-256 vs SHA3-256 vs BLAKE3 internals — live avalanche analysis, Merkle-Damgård/sponge/tree construction diagrams, and timing benchmarks.
Hash Functions
World Hashes
SM3 (China), Streebog (Russia), and Kupyna (Ukraine) alongside SHA-256 and SHA-3. Five-way simultaneous hashing, avalanche analysis, and cryptographic sovereignty context.
KDF Benchmarks
KDF Arena
Live timing and memory comparison of HKDF, PBKDF2, scrypt, and Argon2id with adjustable cost parameters and bar chart visualization.
MAC Primitive
Poly1305 MAC
Polynomial evaluation over GF(2¹³⁰−5), constant-time tag verification, key-reuse attack visualizer, and Polynomial Stepper.
Oblivious Transfer
OT Gate
1-of-2 Oblivious Transfer using the Simplest OT protocol (Chou-Orlandi 2015) over Curve25519 with real Edwards25519 group arithmetic and AES-256-GCM encryption. Foundational primitive for secure MPC.
Stateful Hash-Based Signatures
LMS Ledger
LMS/HSS stateful hash-based signatures (NIST SP 800-208) — W-OTS+ key state grid, one-time key reuse attack with real forgery demo, and CNSA 2.0 firmware signing context.
Merkle Trees
Merkle Vault
Build Merkle trees up to 16 leaves with real SHA-256, generate O(log n) inclusion proofs, tamper any leaf and watch the root change. Git, Bitcoin, and Certificate Transparency walkthroughs.
Nonce Misuse Resistance
Nonce Guard
AES-GCM vs AES-GCM-SIV comparison — live nonce reuse attack showing keystream XOR recovery and GHASH key extraction, synthetic IV construction, and misuse-resistance comparison. RFC 8452.
Pairing Cryptography
Pairing Gate
BLS12-381 bilinear pairing — BLS signature sign/verify with real @noble/curves arithmetic, signature aggregation visualizer (up to 100 signers → 1 proof), and rogue key attack demo. Powers Ethereum 2.0 and Zcash.
IT-PIR
Oblivious Shelf
2-server XOR Private Information Retrieval (Chor et al. 1995) — a patron retrieves any book from a 16-item catalog without the server learning which one was requested. Step-by-step query walkthrough and privacy audit.
Steganography
Stego Suite
LSB substitution, DCT-domain hiding, and adaptive embedding with live chi-squared steganalysis. Hide the message, not just the content.
Threshold ECDSA
GG20 Wallet
GG20 threshold ECDSA — Paillier encryption, distributed key generation, and joint signing without any party holding the full private key. The protocol behind Fireblocks and Coinbase MPC.
Password Hashing
Bcrypt Forge
Bcrypt anatomy, cost factor benchmarking, timing-safe verification, and a real-world breach simulation. The workhorse password hash, dissected.
Blind Signatures
Blind Sign
Chaum RSA blind signatures and Schnorr EC blind signatures — anonymous e-cash, private voting, and unlinkability proofs. The signer signs without seeing the message.
Commitment Schemes
Commit Gate
Hash commitments and Pedersen commitments — binding, hiding, sealed-bid auction, and homomorphic addition. The primitive beneath ZKPs, MPC, and VSS.
PKI & Certificates
PKI Chain
X.509 certificate chains, trust store validation, CA compromise cascades, Certificate Transparency with Merkle inclusion proofs, and post-quantum migration to ML-DSA.
Protocol Composition
Protocol Compose
MAC-then-Encrypt vs Encrypt-then-MAC, padding oracle attack, CRIME, and the composition failures that drove TLS 1.3. Safe primitives composed unsafely break everything.
Ring Signatures
Ring Sign
LSAG ring signatures — key image linkability, double-spend detection, group signatures with manager opening, and Monero transaction privacy. Sign as one-of-many without revealing which.
Threshold Decryption
Threshold Decrypt
ElGamal over P-256 — distributed key generation, verifiable partial decryptions with NIZK proofs, and t-of-n combination without any party holding the full private key.
Steganography
J-UNIWARD
JPEG steganography via Universal Wavelet Relative Distortion — adaptive DCT coefficient embedding that minimizes wavelet-domain detectability. The state-of-the-art in content-adaptive JPEG steganography.
Quantum Threat
Harvest Vault
HNDL pressure, Mosca's theorem, migration windows, and concrete post-quantum planning for the systems being recorded today and decrypted later.
Post-Quantum Isogeny
Isogeny Gate
Elliptic-curve isogenies with a toy CSIDH over GF(419), supersingular graph walks, the Castryck-Decru break of SIDH, and the surviving branches of the field in SQIsign.
Post-Quantum Side-Channel
Lattice Fault
Implementation attacks on lattice PQC: NTT power leakage, rejection-sampling fault bypass, KyberSlash timing, and faulty KECCAK seed injection. The math survives; sloppy implementations do not.
Post-Quantum Cryptanalysis
LLL Break
Step-by-step LLL and BKZ lattice reduction with Gram-Schmidt views, Lovasz condition checks, and a toy LWE primal attack that shows why Kyber-sized parameters do not fall the same way.
Post-Quantum Signatures
MPCitH Sign
Post-quantum signatures from MPC-in-the-Head with additive secret sharing, SHA-256 commitments, Merkle proofs, Fiat-Shamir, and hidden-view challenges over a toy PERK-style witness.
Password-Authenticated Key Exchange
OPAQUE Gate
RFC 9807 OPAQUE aPAKE with live OPRF blind/evaluate/unblind flow, credential-envelope handling, 3DH mutual authentication, and server-breach simulation showing the password never reaches the server.
Verifiable Randomness
VRF Gate
ECVRF prove/verify, Wesolowski VDF repeated squaring, and a RANDAO-plus-VDF beacon simulation that shows how verifiable randomness resists last-reveal manipulation.
Authenticated Encryption
AEGIS Gate
AEGIS-256 from the CFRG draft with AES round-function state updates, six-register sponge flow, tag derivation, and official test-vector verification in the browser.
Lightweight Cryptography
Ascon
NIST's lightweight cryptography standard with Ascon-AEAD128, Ascon-Hash256, avalanche analysis, and side-by-side comparison against AES-GCM and ChaCha20-Poly1305.
High-Security Curves
Curve448
X448 key exchange and Ed448 signatures side by side with Curve25519 and Ed25519, covering the 224-bit security tier for long-lived keys.
ML-DSA Internals
Dilithium Reject
An ML-DSA rejection-sampling lab with live acceptance histograms, rejection-reason breakdowns, and the signing-time tradeoff that keeps lattice signatures secure.
Digital Signatures
ECDSA Forge
ECDSA on secp256k1 and P-256 with sign/verify workflows, RFC 6979 deterministic nonces, and the classic nonce-reuse private-key recovery attack.
Public-Key Encryption
ElGamal Plain
Taher ElGamal's 1985 scheme with fresh ephemeral randomness, multiplicative homomorphism, and ciphertext rerandomization across toy and RFC 3526 groups.
Migration Planning
Harvest Timeline
A harvest-now-decrypt-later risk simulator built around the Mosca inequality, CRQC scenarios, organization profiles, and the operational cost of waiting to migrate.
Post-Quantum Signatures
HAWK
An educational HAWK lab covering integer-only lattice signatures, discrete Gaussian sampling over Z, and the NIST Round 2 additional-signatures landscape.
Post-Quantum Side-Channel
HQC Timing Break
A full-decryption oracle attack on HQC showing how compiler rewrites break constant-time Reed-Muller decoding and expose key recovery through cache timing.
Composite Signatures
Hybrid Sign
Ed25519 plus ML-DSA-65 hybrid signatures per the IETF LAMPS composite-signature draft, framed as defense in depth for long-lived authenticity.
Identity-Based Encryption
IBE Gate
Boneh-Franklin identity-based encryption on BLS12-381 with setup, private-key extraction, encrypt/decrypt flow, and an honest look at the escrow tradeoff.
Post-Quantum Side-Channel
KyberSlash
A KyberSlash timing-attack lab for ML-KEM, covering secret-dependent division, vulnerable compression paths, the Barrett-reduction fix, and live attack simulation.
Hash-Based Signatures
LMS/XMSS
State-managed hash-based signatures with LM-OTS, Merkle trees, and hierarchical composition, showing where LMS, HSS, and XMSS fit in practice.
Lattice Cryptography
NTRU Classic
The original 1996 NTRU lattice cryptosystem with polynomial-ring arithmetic from scratch and the historical path from classic NTRU to modern post-quantum design.
Access-Pattern Privacy
ORAM Vault
A Path ORAM walkthrough with tree buckets, stash growth, position-map updates, and adversary-view visualization for cloud access-pattern hiding.
Additive Homomorphic Encryption
Paillier Gate
Paillier's additive homomorphic cryptosystem with encrypt/decrypt, tallying without decryption, and direct links to voting systems and GG20 threshold ECDSA.
Migration Operations
PQ Rotation
A post-quantum migration planner for hybrid certificates, multi-jurisdiction timelines, rolling key rotation, canary deployment, and rollback strategy.
Post-Quantum TLS
PQ TLS Handshake
TLS 1.3 with the X25519MLKEM768 hybrid handshake, including byte-level framing, full key schedule derivation, and comparison against classical X25519.
Private Set Intersection
PSI Gate
Classic DH-PSI over ristretto255 with RFC 9380 hash-to-curve, showing how two parties learn their overlap (and each other's set size) and nothing more.
Post-Quantum KEM
Scloud+ Vault
China's conservative LWE-based KEM with ternary secrets, BW32 lattice coding, and a faithful but simplified browser model of the ePrint 2024/1306 design.
Threshold Signatures
Threshold ML-DSA
A two-party demo of distributed post-quantum signing that produces real FIPS 204 ML-DSA signatures; key-non-reconstruction is illustrated, not enforced.
Envelope Encryption
Envelope KMS
RFC 3394/5649 AES key wrap, DEK/KEK hierarchy, KMS-style key rotation, re-wrap without plaintext exposure, and a hash-chained audit log — the architecture behind AWS KMS and Google Cloud KMS.
Zero-Knowledge Range Proofs
Bulletproofs
ZK range proofs using Bulletproofs on ristretto255 — 64-bit Pedersen commitments, aggregate proofs over multiple ranges, the inner-product argument, and a tamper-rejection demo.
Lattice Attack
Nonce Lattice
ECDSA nonce-bias lattice attack on secp256k1 and P-256 — Hidden Number Problem construction, in-browser LLL reduction, and byte-for-byte private-key recovery from biased nonces.
Authentication Protocol
Kerberos v5
RFC 4120 Kerberos v5 — Needham-Schroeder origins, Lowe attack, full AS/TGS/AP exchange flow, AES-256-CTS-HMAC-SHA1-96 ticket encryption, and clock-skew replay defense.
Group Messaging Security
MLS Group
RFC 9420 Messaging Layer Security — TreeKEM ratchet tree, epoch key schedule, member add/remove/update operations, and group application messaging with forward secrecy guarantees.
Zero-Knowledge Proofs
ZK Arena
A side-by-side comparison playground for zk-SNARK and zk-STARK proof systems — setup phases, proving overhead, verification cost, and the tradeoff space between Groth16, PLONK, and STARKs.
Few-Time Signatures
Jevil
A hash-based few-time signature scheme over the Goldilocks field using Lagrange interpolation — bounded-use signing with reusable verification keys.
Post-Quantum Side-Channel
Ciphertext Mirror
An ML-KEM side-channel walkthrough — manipulating ciphertexts through the Fujisaki-Okamoto transform, LDPC decoder behavior, and NTT blinding countermeasures.
Post-Quantum Side-Channel
HQC Timing
HQC's BCH decoder leaks timing — observe how constant-time mitigations reshape the attack surface against the standardized code-based KEM.
Post-Quantum Overview
PQ Families
A guided tour of the five post-quantum problem families — lattice, code-based, hash-based, multivariate, and isogeny — with the assumptions, history, and standardization status of each.
Key Exchange Overview
Key Exchange
A walkthrough of key exchange across history and protocol families — from Diffie-Hellman to modern hybrid post-quantum handshakes, with shared assumptions and threat models per era.
Decentralized Trust
Web of Trust
A PGP-style trust graph — sign each other's keys, walk introduction chains, observe how trust flows (and breaks) without a central authority.
Passkeys & Authentication
WebAuthn
Passwordless authentication via FIDO2 / WebAuthn — assertion verification, origin binding, signature counters, and the journey from passwords to passkeys.
Secure Shell Handshake
SSH Handshake
SSH transport-layer handshake and TOFU host-key pinning — ephemeral X25519 / ECDH, Ed25519 signatures over the exchange hash, and known_hosts change detection across StrictHostKeyChecking modes.
HD Wallet Mechanics
Bitcoin Wallet
Bitcoin wallet pipeline in the browser — secp256k1 keys to P2PKH and P2WPKH addresses via HASH160, plus BIP-39 mnemonics, PBKDF2 seed stretching, and BIP-32 hardened child derivation.
Rotor Machine
Enigma Forge
Full mechanical Enigma — rotors with double-stepping, plugboard, and reflector — plus the crib-based Bombe break that exploits the flaw that no letter ever maps to itself.
Polyalphabetic Cipher
Vigenère Break
Encrypt and decrypt with a repeating-key Vigenère cipher, then recover the key length with Kasiski examination and the index of coincidence and solve each column by frequency analysis.
Perfect Secrecy
OTP Vault
One-time pad encryption with provable perfect secrecy, then the two-time-pad break: XOR two ciphertexts under a reused key and crib-drag to recover both plaintexts.
Hash Collisions
Collision Vault
Verify real published MD5 and SHA-1 collision pairs — SHAttered, identical-prefix, chosen-prefix — live in the browser, then watch SHA-256 and SHA-3 resist the same attack.
Token Forgery
JWT Forge
Paste or generate a JWT, tamper with claims, and swap algorithms to watch alg:none and HS/RS key-confusion attacks succeed against a vulnerable verifier and fail against a correct one.
Entanglement-Based QKD
E91
Ekert's entanglement-based QKD: measure entangled pairs, run the CHSH Bell test, and derive a key from aligned bases. |S|≈2.83 proves security; an eavesdropper drags it toward the classical bound, so the key is discarded.
Hybrid PQC
Hybrid Guide
A guide to hybrid post-quantum key exchange — a KEM combiner pairs X25519 with ML-KEM-768 so the session key holds as long as either half survives. Break each component to see the hedge.
Multivariate Signatures
Multivariate UOV
A real Unbalanced Oil-and-Vinegar scheme over GF(256) signs and verifies in the browser, showing how fixing the vinegar variables turns the MQ trapdoor into a linear solve — plus the 2022 Beullens attack that broke Rainbow.
Lattice Cryptanalysis
LWE Hints
Explores approximate-hint LWE secret recovery on sparse ternary secrets — counts how many hints collapse the lattice problem. Computes hint counts; runs no attack. ePrint 2026/1081.
Multi-Instance Degradation
Syndrome Drain
How code-based KEMs erode below NIST Level 1 when one public key derives many session keys — DOOM lets an attacker decode one of D syndromes √D faster. Computes effective security and when to rotate keys.
Leakage Cryptanalysis
Broken Trust
Leak one bit of ML-DSA's per-signature masking randomness and the secret subkey becomes the bottom of a hill you can roll down — no lattice reduction. Watch a toy version descend beside real-scale numbers from ePrint 2026/472.
Bitcoin Script
Bitcoin Script
Step a real P2PKH spend through the Script stack machine — valid, wrong-key, forged-signature, and tampered scenarios, with real secp256k1 and HASH160. No backend.
Diffie-Hellman + MITM
DH MITM
Interactive Diffie-Hellman key exchange, then a live man-in-the-middle attack on the unauthenticated channel that shows why raw DH needs authentication. Real modular arithmetic. No backend.
Hybrid Key Exchange & Signatures
Hybrid PQC
Compare classical, post-quantum, and hybrid key exchange and signatures side by side, then break one half and watch the hybrid survive. Real X25519, ML-KEM-768, Ed25519, ML-DSA-65. No backend.
Merkle Inclusion Proofs
Merkle Proofs
Build a tree, generate inclusion proofs, recompute the root hash by hash, then replay the RFC 6962 second-preimage and CVE-2012-2459 duplicate-leaf attacks. Real SHA-256. No backend.
PAKE Family
PAKE Gate
Tour SRP-6a, J-PAKE, CPace, and Dragonfly (RFC 7664) side by side — a shared key forms from a low-entropy password that never crosses the wire, plus a server-breach toggle and the Dragonblood side-channel.
Threshold Crypto Compared
Shamir vs FROST
Compare Shamir secret sharing against FROST signatures side by side — watch Shamir reassemble the key in memory while FROST signs without it ever existing. Real GF(256) and Ed25519. No backend.
RSW Time-Lock
Time-Lock Puzzle
Seal a message that only sequential squaring can open, then reveal the creator's instant trapdoor that collapses the delay. Real BigInt and AES-256-GCM. No backend.
Timing Side-Channel
Timing Side-Channel
Recover a hidden secret one byte at a time from an early-exit comparison, then watch a constant-time compare flatten the leak. Real performance.now() measurements. No backend.
TLS 1.3 Walkthrough
TLS Handshake
Step through X25519 key exchange, Ed25519 authentication, the HKDF key schedule, and AES-GCM records, with a MITM attack that gets blocked. Real WebCrypto. No backend.
Verifiable Delay Function
VDF
Repeated modular squaring in an RSA group with a Wesolowski short proof — watch sequential work accrue one squaring at a time, confirm parallel workers don't help, then verify instantly and reveal the trapdoor.