Claude Mythos Finds New Attacks on HAWK and AES
> Anthropic says Claude Mythos Preview found a faster HAWK key-recovery attack and a 200–800× improvement against seven-round AES-128 research attacks.
🎧 Listen — ~6 min
Ready · Claude Mythos Finds New Attacks
Anthropic says its Claude Mythos Preview model has helped researchers make two meaningful advances in cryptanalysis: a faster key-recovery attack against the post-quantum signature candidate HAWK, and a major speedup against a deliberately weakened, seven-round version of AES-128.
The important headline is not that internet encryption has suddenly failed. It has not. Neither result breaks deployed AES-128, and HAWK is still a candidate in a NIST standardization process rather than a widely deployed standard. The more consequential story is that a frontier AI system appears able to contribute to original mathematical security research—and to do so quickly enough to become part of how cryptographic schemes are stress-tested before deployment.
What Claude found in HAWK
HAWK is a digital-signature proposal designed for a future in which sufficiently powerful quantum computers could undermine classical public-key systems such as RSA and ECDSA. Its security is based on a hard lattice problem called the Lattice Isomorphism Problem.
According to Anthropic, Mythos Preview identified a previously unexploited symmetry, known mathematically as a nontrivial automorphism, in the lattice structure behind HAWK. Earlier academic work had established that locating such a symmetry could enable a more efficient attack. The missing step was finding one that worked on HAWK's construction. Claude helped find that step.
The resulting method is an end-to-end key-recovery attack on HAWK-256, a small challenge parameter intended for cryptanalysis. Anthropic's public implementation estimates a runtime of about three hours and 42 minutes on a 96-core server. It produces functionally equivalent signing material, sufficient to sign messages accepted by the original public key.
That sounds severe, but scope matters. HAWK-256 is not one of the two NIST security-level parameter sets proposed for deployment. For the larger HAWK-512 and HAWK-1024 parameters, the attack remains impractical. It is also exponential rather than polynomial: the scheme has not been transformed into something trivially breakable.
Still, the research changes the security picture. Anthropic estimates the HAWK-256 attack work factor falls from 2^64 to 2^38. For the larger parameters, the company estimates a lower effective security margin as well. In plain terms, HAWK would need substantially larger keys to retain the same security target, reducing some of the efficiency advantages that made it attractive.
The AES result is not a break of AES-128
The second result concerns AES, the symmetric encryption standard behind countless applications, devices and protocols. Here the qualification is essential: the research applies to seven rounds of AES-128, not the complete 10-round AES-128 used in production.
Reduced-round AES is studied precisely because it helps researchers measure a cipher's safety margin. Anthropic says Mythos developed an invariant fingerprint called the “Möbius Bridge.” In an existing meet-in-the-middle technique, a stage required enumerating 256 possible values. The new fingerprint removes that guessing step, yielding a projected 200- to 800-fold improvement depending on the measurement used.
The attack is nevertheless far from practical. It assumes an attacker can obtain roughly 2^105 chosen plaintexts encrypted with the same unknown key—an extraordinary requirement with no realistic path in ordinary deployments. Anthropic's released artifact validates components of the attack and extrapolates the full seven-round AES-128 cost; it does not perform complete end-to-end recovery of a real AES-128 key.
So there is no operational action for organisations using AES today. No emergency migration is needed, and full AES-128 remains unbroken by this work.
Why this matters for post-quantum security
Post-quantum cryptography is being standardized before cryptographically relevant quantum computers arrive, not after. That gives the community a narrow but valuable window to find weaknesses in candidate schemes through public review, independent attacks and formal analysis.
AI can now become another instrument in that review. Anthropic says Mythos worked in a multi-agent environment with access to research literature, mathematical tools and computational experiments. Human researchers supplied direction, infrastructure and intensive validation. The HAWK result took around 60 hours of model-assisted work and was estimated to cost about $100,000 in API usage; verification still required substantial human effort.
That last detail is reassuring as well as revealing. A model output is not a cryptographic result until experts can reproduce, inspect and challenge it. Anthropic says it coordinated disclosure with the HAWK authors, academics, government and industry partners, and released papers plus demonstration code so the work can be independently examined.
There is a practical governance implication too. Organisations increasingly rely on cryptographic libraries and standards committees to absorb this kind of research before it becomes a production risk. They should preserve crypto agility: maintain an inventory of where signature schemes and encryption are used, avoid designs that make key or algorithm replacement prohibitively expensive, and test upgrade paths before a breaking change arrives. That is sensible engineering regardless of whether the next advance comes from a human academic team or an AI-assisted one.
For vendors and standards bodies, the model-assisted discovery process also makes reproducibility more important. A claim of an AI-generated attack should come with a clear proof, test vectors, runnable artifacts and independent review—not merely an impressive transcript. The public materials released for these findings are a useful model: they make it possible for specialists to evaluate the mathematical claim separately from the story about how it was discovered.
The right response is neither alarmism nor dismissal. AI-assisted cryptanalysis could expose weaknesses earlier, when standards can still be revised and systems are not yet entrenched. At the same time, it raises the bar for scheme designers: new algorithms may face not only years of human scrutiny, but increasingly capable automated research systems working in parallel.
For defenders, the lesson is straightforward. Continue planned migration to approved post-quantum standards, track NIST guidance, and avoid treating any candidate scheme as settled merely because it has survived an initial review round. For researchers, Claude's HAWK and AES work is an early sign that cryptographic evaluation is entering a much more automated era.
What has—and has not—changed
- HAWK-256: Demonstrated key recovery against a challenge parameter.
- HAWK-512 and HAWK-1024: Security estimates are weaker, but the attack is still impractical.
- AES-128 in production: Not broken; the result targets seven of its 10 rounds.
- Other lattice schemes: Not affected by this HAWK-specific finding.
- Security teams: No immediate configuration change is required, but standards monitoring remains important.
The durable takeaway is less about one model or one algorithm. It is that AI is becoming capable of generating hypotheses, testing them against formal structures and helping researchers turn them into reproducible attacks. In cryptography, that capability can be profoundly defensive—provided disclosure, peer review and rigorous verification keep pace.
Sources
- Anthropic: Discovering cryptographic weaknesses with Claude
- Anthropic HAWK key-recovery paper
- The Hacker News coverage
Related reading
Keep reading
Related reading
⚡ Daily AI Model Drop — Get Kimi K3 benchmarks before Twitter
Join 2,400+ AI engineers. 1 email/day, no spam, unsubscribe anytime