01▲Enhanced Differential-Linear Cryptanalysis of ChaCha Based on Bit Puncturing eprint.iacr.org New differential-linear attack on ChaCha, with bit puncturing and key guessing shaving time off 7 and 7.5-round key recovery.cha-chacryptanalysiseprintstream-ciphersymmetric-crypto0 pts/adamd/11 days ago/discuss