" approves the use of the key combiner (14) for any t > 1 if at least one shared secret ... is generated from the key-establishment methods in SP 800-56A [1] or SP 800-56B [2] or an approved KEM." they're even chiller about the ordering than before nvlpubs.nist.gov/nistpubs/Spe...
sub exponential attack on McEliece (for now doesn't impact Classic McEliece) eprint.iacr.org/2026/1232.pdf