" the attack has shaken cryptographers’ confidence in the Fiat-Shamir protocol, and the random oracle model more generally"