Skip to content
worth noting Security

The model Mythos from Anthropic found weaknesses in the cryptographic schemes HAWK and AES

confirmed by 2 independent sources

The model Claude Mythos Preview from Anthropic largely independently discovered an improved attack on the post-quantum scheme HAWK and a new attack on a weakened version of AES-128. According to the company, this does not threaten current systems.

Anthropic said that its model Claude Mythos Preview discovered mathematical weaknesses in two cryptographic schemes: it improved an attack on the post-quantum signature scheme HAWK and developed a new attack on a weakened version of the AES-128 cipher (a version with 7 of 10 rounds). According to Anthropic, neither finding threatens systems deployed in production – HAWK is only a candidate in the third round of the NIST standardization process, and the tested version of AES is not the one commonly used.

For HAWK, the model worked largely independently in a multi-agent system and found an improved attack based on a previously undetected symmetry in the mathematical lattice in 60 hours, while human experts had been studying the scheme for over two years. One agent initially deemed the idea infeasible, but another fully exploited it. According to Anthropic, a human researcher with a theoretical background in computer science, but no expertise in lattice-based cryptography, focused mainly on project management. For AES, the model initially refused the task, saying that further improvement was impossible, and only after being prompted to look for “truly new ideas” did it develop a method called Möbius Bridge, which, according to Anthropic, improves on the best existing attacks by a factor of 200 to 800. Over three days, the model generated roughly a billion tokens and received only three substantive instructions from a human. API costs for the two tasks reached roughly 100 000 dollars; human researchers without cryptographic expertise then spent hundreds of hours verifying the results.

Ars Technica adds important caveats to the results: these are incremental improvements, not a breach of systems in use; the tested variants are deliberately weakened “challenge” versions intended for independent assessment, and the methods used would probably not be feasible outside the testing environment. According to Ars Technica, it is not yet possible to distinguish precisely how much of the presentation from Anthropic is marketing and how much is a substantive result.

Anthropic shared the results in advance with the US government, industry partners and the authors of the HAWK scheme. Together with researchers from ETH Zurich, Tel Aviv University and the University of Haifa, it also created the CryptanalysisBench benchmark to systematically evaluate the cryptanalytic capabilities of language models. The model Mythos Preview remains unavailable to the public; according to Ars Technica, only a limited group of trusted users has access to it.

What changed

Why it matters

This is not a breach of encryption used in practice today, but a demonstration that an AI model can find nontrivial mathematical weaknesses beyond those identified through human review in both candidate and weakened versions of cryptographic schemes, orders of magnitude faster than a team of experts. This is particularly relevant to standardization processes (e.g. NIST for post-quantum cryptography), where such tools may become part of future adversarial testing before a standard is finalized.

Two audiences, two different impacts

What this means

01

For individuals

For people working in cryptography or security research, this signals that AI models may discover sophisticated attacks faster than a human team, changing both research possibilities and the demands of subsequent verification of results.

What to do Watch for the release of the CryptanalysisBench benchmark if testing the cryptanalytic capabilities of AI models is relevant to your work.
More practical updates →
02

For a business

Companies selecting or developing cryptographic standards, especially post-quantum candidates such as HAWK, should monitor standardization developments at NIST and account for the possibility that AI tools may uncover weaknesses in schemes that have not yet been finalized sooner than expected.

Risks and compliance
What to decide Monitor the status of HAWK standardization at NIST and any follow-up reports before making decisions about deploying post-quantum cryptographic schemes.
More business impacts →
AES Anthropic security Claude Mythos HAWK cryptanalysis cryptography Mythos post-quantum cryptography

Check the original

Event sources

confirmed by 2 independent sources · 2 publishers, 2 independent. We count feeds from the same owner only once.

2
The Decoder (daily AI news) independent context · first detected Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet Ars Technica (AI) independent context Mythos uncovers crypto weaknesses that went unknown for years