https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu...
To make things even worse than rolling their own hash function, they're claiming the flaw was intentional! This makes them hostile and untrustworthy to the open source community if this is true and further erodes confidence they know what they're doing if this is their attempt at PR spin:
https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
> Next, and in my mind most damningly, Sergey Ivancheglo, Iota’s cofounder, claims that the flaws in the Curl hash function were in fact deliberate; that they were inserted as ‘copy protection’, to prevent copycat projects, and to allow the Iota team to compromise those projects if they sprang up.
The creator requested an open, live debate to put these claims to rest. They haven't accepted and probably won't.
With its use, the scarcity of numbers remain, that is, finding a clash that would allow to forge a transaction stays infeasible, and mining stays hard.
BTW while mining is so important with Bitcoin and Etherium, it's not a necessary part of a cryptocurrency. Mining is an incentive to keep doing blockchain validation. Some currencies exist without it (e.g. NXT).
Post-quantum cryptograph research is a very active area right now. If these researchers do not find a practical signature algorithm, PKI as we know it will change very significantly.
Ironically, blockchains might elevate in importance as a result, since the evolving blockchain is a useful construct for quantum resistance. It has cryptographic agility built in.