Published by Emerging Technologies Laboratory · via ETL Newswire
Technology· 

Anthropic's Claude Mythos Breaks a Post-Quantum Signature Candidate in 60 Hours

An unreleased Anthropic model found a structural flaw in HAWK, a NIST-reviewed post-quantum scheme, that two years of human cryptanalysis had missed, raising pointed questions about AI's role in standards review.

By Theo Okafor, Staff Reporter · Technology Desk

Anthropic published findings on July 28 showing that its restricted frontier model, Claude Mythos Preview, improved the best-known attack on HAWK, a digital signature scheme currently in NIST's third round of post-quantum standardization review. The result did not break any deployed system, but it did something the cryptography research community had not managed in two years of expert scrutiny: it found a meaningful structural weakness in a candidate that was still in contention.

According to Anthropic's own research blog, the model worked semi-autonomously for roughly 60 hours and at an API cost of around $100,000 to produce the HAWK result. The attack exploited what the company called a nontrivial automorphism in HAWK's lattice structure, a symmetry that prior analysis had not leveraged. The practical effect was significant: as reported by TechBriefly, the HAWK-256 key-recovery cost fell from roughly 2^64 operations to 2^38 operations, cutting the scheme's effective security roughly in half.

The second finding involved 7-round AES-128, a reduced variant researchers use as a test target. The full 10-round cipher is not affected, and Anthropic was explicit about that. Still, according to coverage in The Hacker News, the model developed a technique it named the Möbius Bridge, building on meet-in-the-middle methods and removing a guessing step that had required checking 256 values, making the attack 200 to 800 times faster than the previous best depending on the metric used. Anthropic told CyberScoop the AES-related discovery was nearly fully autonomous after light human prompting over several days.

The important caveat is that HAWK-256 is a challenge parameter provided as a cryptanalytic target, not a production parameter. As The Hacker News noted in its review, NIST's active parameter sets are HAWK-512 and HAWK-1024, and as of July 29 NIST still listed HAWK as a third-round candidate. Anthropic said it followed coordinated disclosure practices, notifying HAWK's designers in June before the public release.

There's an architecture story underneath the headline. The Anthropic research blog explains that researchers had to keep redirecting Mythos toward harder, publication-quality attacks rather than letting it switch to easier targets. That's not a fully autonomous cryptanalyst; it's a capable system that still needs expert steering to stay on hard problems. Independent researchers had not reproduced either result as of the reporting date, which is worth holding onto before anyone claims a new era of push-button cryptanalysis.

To build out the evaluation infrastructure, Anthropic partnered with academics at ETH Zurich, Tel Aviv University, and TU Berlin on a 191-task benchmark called CryptanalysisBench, released July 20, designed to let others measure AI cryptanalytic performance systematically. According to The Hacker News, five models broke between 65% and 86% of its easier first-tier schemes.

What this actually demonstrates is narrower and more interesting than the headline version. A frontier model, given expert direction, meaningful compute, and a well-scoped mathematical target, can find structural weaknesses that slip past human reviewers working at conventional pace. That has clear value for standards bodies willing to integrate AI-assisted review before finalization, not as a replacement for cryptographers, but as a way to run more attack surface before a scheme ships. The HAWK team now has data it did not have before. That's the useful framing. The alarmist one is not supported by what Anthropic actually published.

Sources cited:
- Anthropic Research Blog (https://www.anthropic.com/research/discovering-cryptographic-weaknesses)
- TechBriefly (https://techbriefly.com/2026/07/29/claude-mythos-finds-weakness-in-hawk-encryption-candidate/)
- The Hacker News (https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html)
- CyberScoop (https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/)

Reporting by Theo Okafor, Staff Reporter, for the Technology desk · ETL Newswire staff
Read more at the source

This release was originally distributed via ETL Newswire. Visit Anthropic Research Blog for the full story, related releases, and contact information.

Visit Anthropic Research Blog →