A post-quantum signature can fail in the math or in the code.
Last week, two papers showed one of each. Both schemes, SNOVA and MAYO, are still under NIST evaluation, which is exactly when you want this found.
➤ SNOVA's signing code leaked secret keys.
IBM Research showed that SNOVA's signer picks some random values slightly more often than others. That small bias was enough to recover secret keys for four of its alternative settings, using 9 to 180 million signatures. The recommended settings weren't affected by this bug, and picking the values evenly would close it.
➤ New math pushed MAYO to change its settings.
Researchers at ETH Zurich and Radboud found a cheaper way to attack this family of signatures. By their estimates, four of MAYO's alternative Round-2 settings fall below their claimed security. After a private heads-up, the MAYO team dropped a setting planned for Round 3 and raised its parameters.