Anthropics Claude Mythos Uncovers New Attacks on HAWK and AES Cryptographic Schemes
The first breakthrough is an improved attack on HAWK, a lattice‑based signature scheme that is a third‑round candidate in the U.S. National Institute of Standards and Technology (NIST) post‑quantum cryptography (PQC) standardization process. Claude Mythos Preview autonomously discovered the attack after a week of literature review, mathematical reasoning, and computational verification. The result halves the effective key size of HAWK‑256, reducing its theoretical security level from 2^264 to 2^238 operations. The researchers communicated the finding to HAWK’s authors in June and coordinated a public disclosure to the NIST mailing list.
The second attack focuses on a 7‑round version of AES‑128. While AES, adopted by NIST in 2001, normally employs 10 rounds for 128‑bit keys, the researchers used a multi‑agent harness and a custom scaffold that enabled Claude to pose hypotheses, run experiments, and design an attack. The new method, dubbed a Möbius Bridge, refines a meet‑in‑the‑middle attack by eliminating a 256‑fold search factor. The resulting attack is 200‑to‑800 times faster than the best prior attack on 7‑round AES, which required 2,105 chosen‑plaintexts. The research was completed in about a week of autonomous work, with significant human effort devoted to validating the algorithm.
Both attacks apply only to weakened or reduced‑round versions of the algorithms and do not affect production systems that use full‑strength HAWK or AES. HAWK is not yet deployed, and the AES attack targets a 7‑round variant used primarily for academic study. The researchers emphasized that the findings do not compromise current cryptographic deployments.
This work is part of a broader initiative by Anthropic to assess the cryptanalytic capabilities of large language models. The team partnered with academics at ETH Zurich, Tel Aviv University, and the University of Haifa to create CryptanalysisBench, a benchmark that packages many cryptographic primitives for evaluation. The research was conducted under responsible‑disclosure procedures, with consultations from academics and advance copies shared with U.S. government and industry partners.
The results are documented in two technical papers that include full proofs, implementation details, and performance measurements. The papers are available to the research community and are currently under review by the cryptographic community.
The findings demonstrate that advanced AI models can discover vulnerabilities in algorithms that have survived extensive human scrutiny. While the attacks do not threaten existing systems, they illustrate the potential for AI‑assisted cryptanalysis to shape future standardization and security reviews.
Anthropic has stated that it will continue to explore cryptographic research with Claude Mythos and will publish additional results as they are validated. The company also plans to use CryptanalysisBench to track the evolution of language‑model capabilities in cryptanalysis.
The broader implication is that AI models may become a routine tool for cryptographic vetting, potentially accelerating the identification of vulnerabilities in both new and legacy algorithms. The research community is encouraged to engage with these findings and consider how AI can be integrated into existing security review processes.
The research is currently under review by the cryptographic community and is expected to be cited in future standardization discussions. Anthropic has not announced any immediate changes to its product offerings as a result of these findings.