8/3/2026, 1:03:41 PM · evaluation-safety

Anthropic's Claude Mythos Uncovers Novel Attacks on HAWK Post-Quantum Signature Scheme and Reduced-Round AES

Using approximately $100,000 in API compute, Anthropic's Claude Mythos Preview model autonomously discovered a key-recovery attack that forced HAWK's withdrawal from NIST's post-quantum standardization process and devised a 200–800× faster attack on a research variant of AES.

Background

<cite index="5-11,5-12">The U.S. National Institute of Standards and Technology (NIST) has been conducting a near decade-long effort to standardize new Post-Quantum Cryptographic (PQC) schemes, an effort that has grown critical as the horizon to building a cryptographically-relevant quantum computer shrinks and threatens classical cryptography such as RSA and ECDSA.</cite> <cite index="3-10,3-11">HAWK is a digital signature system — the mathematical mechanism that proves a transaction's origin without exposing a private key — built to survive future quantum computers; NIST advanced it into the third round of its post-quantum signature competition in May 2026, where it was the last lattice-based candidate standing.</cite>

The HAWK Finding

<cite index="4-5,4-6">Anthropic said Mythos Preview developed and verified the HAWK result over approximately 60 hours in a multi-agent environment, with a human researcher providing occasional project-management guidance but no specialist lattice-cryptography expertise.</cite> <cite index="5-13,5-14,5-15">HAWK's security is based on the hardness of the Lattice Isomorphism Problem; Mythos's attack works by finding a specific, previously unexploited symmetry called a nontrivial automorphism in the lattice used by HAWK — prior work had proved that efficiently finding such an automorphism would permit an attack, but had not confirmed whether such an automorphism was accessible in HAWK's lattice.</cite>

<cite index="7-13">For the smallest HAWK configuration, the cost of recovering a secret key fell from 2^64 operations to 2^38 — roughly 67 million times less work.</cite> <cite index="9-7">Key recovery subsequently runs in approximately 3 hours and 42 minutes on a 96-core server.</cite> <cite index="7-15">Anthropic noted that "doubling HAWK's key size eliminates many of the reasons making the scheme an attractive PQC signature candidate."</cite>

<cite index="4-12,4-13,4-14">Later on July 29, 2026, the HAWK team withdrew HAWK from NIST's additional post-quantum signature standardization process after confirming that Anthropic's attack approximately halves the block size required in lattice reduction to recover an equivalent secret key; the team concluded that straightforward mitigations — including doubling parameters or moving to higher-rank modules — would make HAWK uncompetitive, and NIST subsequently updated its third-round candidate page to mark HAWK as withdrawn.</cite>

The AES Finding

<cite index="1-7,1-8,1-9">The second attack is based on a new cryptanalytic technique, dubbed "Möbius Bridge," which improves attacks against a weakened version of Advanced Encryption Standard (AES)-128 using only seven "rounds" instead of the full-strength version's ten — rounds being the repeated series of mathematical transformations that AES and other encryption algorithms apply to protect data, with reduced-round variants commonly studied to evaluate security margins of block ciphers.</cite> <cite index="2-3">The new technique produces an attack that is 200 to 800 times faster against the seven-round research version.</cite> <cite index="4-1,4-2">The AES result applies to seven of AES-128's ten rounds, still requires an impractical number of chosen plaintexts, and Anthropic said no production software needs to change as a result.</cite>

Cost and Methodology

<cite index="4-7">Anthropic put the application programming interface (API) cost of each discovery at about $100,000.</cite> <cite index="5-4,5-5">The research relied on a scaffold — a set of prompts and code that help the model achieve its goal — built on top of Claude Code, constructing an environment where the model could safely run experiments and log results.</cite> <cite index="3-4,3-5">The HAWK research paper itself was notable for transparency in its division of labor: "The majority of mathematical discoveries in this paper were AI-assisted," with human author contribution "mainly consist[ing] of directing, organizing and verifying AI work."</cite>

Responsible Disclosure and CryptanalysisBench

<cite index="16-2,16-3,16-4">Throughout the research process Anthropic followed responsible disclosure procedures and consulted academics to confirm the validity of findings; the company also shared advance copies with U.S. government and industry partners and, in the case of the HAWK finding, shared the attack with HAWK's authors in June and coordinated disclosure to the public NIST mailing list at the same time results were released.</cite>

<cite index="16-1">To facilitate further study of the cryptanalytic ability of large language models (LLMs), Anthropic partnered with academics at ETH Zurich, Tel Aviv University, and TU Berlin to build CryptanalysisBench, a benchmark that packages together many cryptographic ciphers and makes it easier for others to evaluate LLM capabilities on the topic.</cite>

<cite index="13-4">Anthropic predicts a similar dynamic to AI-driven software vulnerability discovery will arrive in academic cryptography: as language models produce novel research outputs autonomously, human researchers will increasingly become bottlenecked on studying and validating results for technical validity, novelty, and utility.</cite> The company has published a proof-of-concept on GitHub at `github.com/anthropics/cryptography-research-demo`.

Cross-references

Sources

  1. [1]
    Anthropic finds weakness in Hawk post-quantum digital signature algorithm | CSO Online
  2. [2]
    AI Finds New Weaknesses in Cryptographic Algorithms, Anthropic Says
  3. [3]
    Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break - Decrypt
  4. [4]
    Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
  5. [5]
    Discovering cryptographic weaknesses with Claude \ Anthropic
  6. [6]
    Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop
  7. [7]
    Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break
  8. [8]
    Claude found mathematical flaws in two cryptographic algorithms that years of expert review missed
  9. [9]
    Claude Breaks Post-Quantum HAWK Cipher in Just 60 Hours | byteiota
  10. [10]
    Anthropic’s Transparency Hub \ Anthropic
  11. [11]
    Observations on Anthropic’s Vulnerability Disclosure Ledger | Blog | VulnCheck
  12. [12]
    AI Cracks Post-Quantum Cipher in 60 Hours After Two Years of Human Review Failed
  13. [13]
    Claude Mythos finds attacks on HAWK and reduced AES | ETIH EdTech News — EdTech Innovation Hub
  14. [14]
    Anthropic Responsible Disclosure Policy: Glasswing CVD Explained
  15. [15]
    Responsible Disclosure Policy
  16. [16]
    www.mexc.com