Resolution criteria
This market resolves to YES if a fatal flaw is identified in Daniel R. Simon's paper, "A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem" (IACR ePrint 2026/1591), that invalidates its primary claim of presenting a polynomial-time quantum algorithm for the Dihedral Coset Problem (DCP).
This includes any of the following events:
The paper is formally withdrawn or retracted by the author or the IACR Cryptology ePrint Archive.
The author publishes an updated version, erratum, or public statement acknowledging that the proposed algorithm contains a fundamental error and the main result does not hold.
A peer-reviewed paper, preprint, or widely accepted analysis by prominent researchers is published showing a clear, unfixable error in the mathematical proofs or algorithm design, resulting in a general consensus in the cryptographic community that the paper's main claim is incorrect.
This market resolves to NO if the paper’s primary claim remains standing and is not refuted by the market's closing date. Peer-reviewed acceptance and publication of the paper in a major cryptography or theoretical computer science conference (e.g., CRYPTO, EUROCRYPT, STOC, FOCS) without subsequent retraction will also lead to a NO resolution.
Background
On August 6, 2026, Daniel R. Simon (the AWS cryptography researcher known for Simon’s algorithm) published a preprint on the IACR Cryptology ePrint Archive titled "A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem".
The paper claims a polynomial-time quantum algorithm for the Dihedral Coset Problem (DCP). Because long-established reductions connect the DCP to approximate lattice problems and the Learning With Errors (LWE) problem, a valid polynomial-time quantum algorithm for DCP could have major theoretical implications for the security of lattice-based post-quantum cryptography standards like ML-KEM. However, the proposed algorithm relies on extremely high-degree polynomial complexity (requiring a very large number of quantum samples), meaning it does not constitute a practical attack on current systems. Because this is an un-peer-reviewed preprint, the cryptographic and quantum computing communities are actively scrutinizing the proof for potential errors or gaps.