Anthropic AI cracks post-quantum cryptography and finds faster AES attack autonomously

Reviewed byNidhi Govil

5 Sources

Share

Anthropic's Claude Mythos Preview discovered mathematical weaknesses in two cryptographic algorithms after years of expert review missed them. The AI halved HAWK's key strength in 60 hours and found a 200-800x faster attack on seven-round AES-128. While no production systems are affected, the breakthrough signals AI's growing capability to challenge core internet security assumptions.

Claude Mythos Preview Discovers Mathematical Flaws in Cryptographic Algorithms

Anthropic AI has announced that Claude Mythos Preview, its unreleased advanced model, independently discovered previously unknown mathematical weaknesses in two cryptographic algorithms that survived years of expert human review

1

. The findings target the HAWK post-quantum signature scheme, currently competing for NIST standardization, and a reduced version of the Advanced Encryption Standard that protects online transactions and communications worldwide

2

. This represents a qualitative leap in AI capabilities—moving from finding implementation bugs in cryptographic libraries to discovering flaws in the mathematics of the algorithms themselves

3

.

Source: Decrypt

Source: Decrypt

HAWK Attack Cuts Key Strength in Half Through Hidden Symmetry

The first breakthrough involves HAWK, the only lattice-based cryptography candidate among nine schemes that NIST advanced to the third round of its post-quantum digital signature process in May 2026. Claude Mythos Preview worked semi-autonomously for approximately 60 hours at roughly $100,000 in API costs to derive an end-to-end key-recovery attack against HAWK-256

5

. The attack exploits a previously unused symmetry—described as a nontrivial automorphism—in the lattice structure behind the digital signature scheme.

Anthropic's implementation reduces the expected HAWK-256 key-recovery work factor from 2^64 to 2^38 operations, roughly 67 million times less work

4

. For the production-level parameters, gate-count estimates fell from 2^150 to 2^108 for HAWK-512 and from 2^288 to 2^182 for HAWK-1024, though both larger parameters remain impractical to attack. The attack remains exponential and does not extend to other NIST candidates or lattice-based cryptography generally

5

.

Möbius Bridge Attack Accelerates Reduced-Round AES Cryptanalysis

The second result targets seven-round AES-128, a reduced version of the cipher that scrambles HTTPS traffic, encrypted drives, and backend systems across the internet

4

. Full AES-128 uses ten rounds of scrambling; studying reduced-round AES is standard cryptanalytic practice to measure safety margins before an attack reaches the full construction. The model developed what Anthropic calls the Möbius Bridge, a fingerprinting technique that removes a 256-way guessing step from existing meet-in-the-middle attacks

5

.

Source: Hacker News

Source: Hacker News

This innovation produced an attack 200 to 800 times faster than previous methods, improving on work that had stood since 2013

4

. The discovery was almost fully autonomous after researchers sent just three substantive prompts over three days

3

. Initially, Claude refused the task, stating there was "nothing easy to find" in "the most-studied block cipher in existence"

4

. After encouragement, the model produced one billion output tokens and invented the technique that broke the longstanding barrier

3

.

Human Verification Becomes the Bottleneck as AI Finds Flaws in Encryption

While Claude discovered the AES weakness in days, Anthropic researchers spent several hundred hours learning enough cryptography to confirm the result worked

4

. The HAWK paper states explicitly that "the majority of mathematical discoveries in this paper were AI-assisted" with human contribution "mainly consist[ing] of directing, organizing and verifying AI work"

4

. A human researcher provided occasional project-management guidance but was not a lattice-cryptography specialist.

Anthropic warned that human verification may become the limiting factor as models accelerate discovery. "The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up"

4

. The company previously reported that Claude Mythos found 10,000 critical software vulnerabilities in one month and 271 vulnerabilities in Firefox during internal testing

3

.

Broader Implications for Internet Security and Post-Quantum Standards

Anthropic emphasized that neither result affects production systems. HAWK has never been deployed, and the AES attack requires an impractical number of chosen plaintexts—about 2^105—and only works against seven of ten rounds. However, the long-term implications could reshape internet security assumptions

2

. In previous tests, large-language models could not match human performance in mathematically dense cryptanalysis, but these breakthroughs suggest AI may soon challenge foundational protections

2

.

Anthropic disclosed follow-up results including a practical attack on 13-round LEA—a Korean national and ISO lightweight-encryption standard—that recovers keys in under an hour on a desktop, plus attacks on Serpent-128, Salsa20, Poseidon, and SHA-1

3

. The company partnered with ETH Zurich, Tel Aviv University, and University of Haifa to release CryptanalysisBench, a benchmark with 191 cipher-breaking tasks for evaluating AI cryptanalytic capabilities

3

. Mythos scored 85.7% on tasks with known solutions but under 9% against full-strength ciphers with no published break

4

.

Anthropic followed responsible disclosure, coordinating with HAWK's authors, NIST, U.S. government, and industry partners before publication

3

. The company noted that while the White House launched Gold Eagle to coordinate AI-powered cyber defence, no equivalent programme exists for cryptographic review

3

. "In just one year, language models have gone from being unable to perform cryptanalysis of even the most basic ciphers to being capable of finding flaws in cryptographic designs that have escaped discovery despite years of human expert review," Anthropic wrote, raising a critical question: what happens when a model finds a flaw in a cipher already protecting production systems[3](https://thenextweb.com/news/anthropic-claude-mythos-cryptographic-attacks-hawk-aes]?

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved