Anthropic's Claude Mythos Discovers New Weaknesses in Cryptographic Algorithms
Key Takeaways
- ▸Claude Mythos autonomously discovered an improved attack on HAWK, a post-quantum signature scheme, cutting its key strength in half in just 60 hours of work
- ▸Second breakthrough identifies a novel attack on round-reduced AES that improves attack speed by 200-800x compared to previous best-known methods
- ▸Results demonstrate AI's ability to discover mathematical flaws in cryptographic algorithms, not just implementation bugs in cryptographic libraries
Summary
Anthropic announced that Claude Mythos Preview, its frontier AI model, has discovered improved attacks against two important cryptographic algorithms. The first attack targets HAWK, a post-quantum digital signature scheme under consideration by NIST, effectively cutting its key strength in half after just 60 hours of autonomous work—despite HAWK having survived two rounds of expert human review over two years. The second discovery identifies a new attack vector against round-reduced AES, the world's most widely-used symmetric cipher, improving attack speed by 200-800x over previous methods.
While both discoveries represent significant research advances, Anthropic emphasizes that neither finding poses immediate practical risks to existing systems. HAWK remains an undeployed candidate in NIST's post-quantum cryptography standardization process, and the AES attack applies only to deliberately weakened research variants, not the full production cipher. Nevertheless, the results demonstrate that frontier AI models like Claude Mythos can autonomously discover mathematical flaws in cryptographic algorithms—a capability that could reshape how researchers stress-test security systems before and after real-world deployment.
- No impact on production systems; HAWK is undeployed and AES attack targets reduced versions only
- Marks potential shift in cryptographic research: AI-driven stress-testing of algorithms could accelerate discovery of flaws before real-world deployment
Editorial Opinion
These findings represent a watershed moment for cryptographic research: an AI model discovering mathematical flaws in foundational security algorithms without human intervention is both exciting and sobering. On one hand, this capability could dramatically improve the speed and thoroughness of cryptographic stress-testing, making systems more robust before deployment. On the other hand, it signals that the era of purely human-driven cryptanalysis may be ending, raising urgent questions about how quickly cryptographic standards must adapt as AI models become more capable.

