From the paper:

“At least four Dilithium software vulnerabilities have been announced so far, including an identical vulnerability in each of the two official Dilithium 1.0 implementations and two different vulnerabilities in a “verified” implementation of Dilithium 3.4, also known as ML-DSA. However, there do not appear to have been any demos showing exploitability of any of these vulnerabilities.

This paper shows that a small change in ML-DSA software creates an ML-DSA version of the Dilithium 1.0 software vulnerability, can occur by accident as in the original vulnerability, interoperates with authentic ML-DSA, passes typical tests, and is exploitable in 1 second on 1 laptop core. This paper provides an open-source attack demo that inspects a public key and two signatures, obtains an equivalent secret key, and uses this key to rapidly forge signatures on attacker-chosen messages. […]”