Summary: We introduce a new cryptanalytic technique based on Wagner’s boomerang and inside-out attacks. We first describe this new attack in terms of the original boomerang attack, and then demonstrate its use on reduced-round variants of the MARS core and Serpent. Our attack breaks eleven rounds of the MAPS core with $$2^{65}$$ chosen plaintexts, $$2^{70}$$ memory, and $$2^{229}$$ partial decryptions. Our attack breaks eight rounds of Serpent with $$2^{114}$$ chosen plaintexts, $$2^{119}$$ memory, and $$2^{179}$$ partial decryptions.
