We show that the CRT-FHE scheme of Pradhan et al. is insecure for laws within its assumed error distribution range. The secret key follows from the public key by a single ring inversion whenever the public multiplier is a unit. The plaintext is recovered from any ciphertext under such a law without the secret key, for every multiplier, giving chosen-plaintext advantage 1/21/2. We further show that the transformation from ordinary Ring-LWE to CRT-RLWE does not preserve the error distribution, so it does not establish that CRT-RLWE is at least as hard as Ring-LWE.

One mechanism underlies both. The Chinese remainder theorem (CRT) function is reduced modulo p1p2p_1p_2 while its output is used modulo a coprime modulus qq, so under every zero-preserving section an error in p2Rp_2\mathcal{R} encodes to zero. The law p2B1p_2B_1 is so confined, meets the stated conditions, and decrypts correctly. Confinement is not a weakness of scale: scaling any baseline law by p2p_2 leaves its ordinary Ring-LWE problem exactly equivalent, while the reduced encoder destroys every error it produces. The reduction discrepancy is a multiple of p1p2p_1p_2 and not of qq, so the small-error premise of the proof cannot remove it, and at the reported parameters a single error coefficient refutes the identity while satisfying that premise. The centered binomial B2B_2 separates the coefficient laws at total variation distance 3/83/8, and at the reported dimension that distance between the induced polynomial laws is exponentially close to one.