> In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system secure is low — Bruce Schneier (about IOTA)
OK, it looks like the answer is they designed a custom hash function because their system is built with ternary logic (?!?):
https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
... because "Ternary is the optimal radix" according to their cofounder:
> Ternary is the optimal radix, actually Base E (2.71....) is, but you can't make processors like that. So it comes down to Base Binary (2) vs Base Ternary (3). 3 is closer to the universal optimum 2.71 than is 2. That is the absolute most simple elevator pitch for ternary.
https://iota.stackexchange.com/questions/8/why-does-iota-use...
Reading about the design of this system, I feel like I just entered the twilight zone, or maybe the website for Time Cube. Urbit makes more sense than this. (The design of Urbit makes fine sense, it's just the implementation is extremely obscure.)