ChaCha20 Variants in the Wild

Written by Dominik Pantůček on 2026-10-08

researchcryptography

You use ChaCha20 as your symmetric stream cipher of choice for encrypted containers and then you try to map those containers on a simple TLS connection. If you really tried, you've already noticed the issue. ChaCha20 is NOT a single cipher anymore.


Although all the available cipher specifications use the same block function there is an important difference in the state initialization procedure.

In the original design the initial state before applying the cipher rounds is as follows where each letter represents 32 bits:

c c c c
k k k k
k k k k
b b n n

The letters have the following meaning:

  • c - a constant value
  • k - 256-bit key
  • b - block number (counter in the original design)
  • n - nonce

The first four constant values are four four-byte values taken from the following ASCII string: "expand 32-byte k" which acts as nothing-up-my-sleeve number.

One of the benefits of ChaCha20 is that although it is a stream cipher, computing a particular block of the key stream is possible without having to go through the whole stream.

This original design also allows for encrypting 2 64 blocks of 64 bytes - 1ZiB using one key and nonce.

And here comes the other variant of our favourite cipher. The ChaCha20 for IETF Protocols as specified by RFC 8439. The road to hell is always paved with good intentions, isn't it? This particular instance of such road was prompted by an added requirement to use longer nonce of 96 bits.

The updated initial state is as follows:

c c c c
k k k k
k k k k
b n n n

Such decision, however, means that only half of the bits reserved for the block number (counter) remain. And therefore only 2 32 blocks of 64 bytes - 256 GiB can be encrypted using this variant of the cipher using one key and nonce.

Therefore if you want to transfer contents of a container encrypted using the original design through the TLS connection which uses the longer nonce variant, you're screwed.

Hope you liked our little venture into same-yet-incompatible ciphers and don't forget to tune in next time for more weird stuff.