Greg Rose posted this to the NIST forum:
I'm just back from vacation, but I can confirm that (with minor tweaks and a slight increase in complexity) this attack works. Rats. I believe a simple fix is possible, and after sleeping on it for a few weeks will probably release a new version, but for the purposes of NIST, I think my submission is dead.
Does this mean we can label this submission "broken" on the SHA-3 Zoo page?