On this page3 sections
Claude Mythos Preview has discovered significant mathematical flaws in cryptographic algorithms themselves, marking a shift from finding implementation bugs to breaking the underlying mathematics.
Anthropic researchers used their frontier model to develop two major attacks over just one week of work. The first substantially weakens HAWK, a post-quantum digital signature scheme under review by NIST for standardization. The second identifies a new method to attack reduced-round AES, the world's most widely used symmetric cipher.
Breaking post-quantum cryptography
The HAWK attack represents the most significant finding. HAWK is a third-round candidate in NIST's search for quantum-resistant digital signatures — cryptographic systems that would remain secure even against future quantum computers.
Despite surviving two years of expert human review, Mythos cut HAWK's effective key strength in half within 60 hours of autonomous work. The attack exploits a previously unknown symmetry in the Lattice Isomorphism Problem that underpins HAWK's security.
The discovery cost approximately $100,000 in API calls to develop. Anthropic shared the findings with HAWK's authors in June and coordinated public disclosure through NIST's mailing list.
Accelerating AES cryptanalysis
Mythos also discovered an improved attack against round-reduced AES, the encryption standard adopted by NIST in 2001. While the attack only works on weakened versions studied in academic research, it eliminates one attacker guess and speeds up previous methods by 200-800 times.
The model achieved this breakthrough fully autonomously using a scaffold built by Anthropic researchers, requiring no human intervention during the discovery process.
Broader implications
Neither result affects production systems today. HAWK remains a candidate scheme not yet deployed, while the AES attack only works on reduced versions that don't match the full cipher used in practice.
However, the findings demonstrate frontier AI's potential to discover cryptographic vulnerabilities both before and after real-world deployment. Anthropic has since broadened its search and discovered additional attacks.
The company partnered with academics at ETH Zurich, Tel Aviv University, and TU Berlin to create CryptanalysisBench — a benchmark allowing others to evaluate LLM capabilities in cryptographic analysis.
Anthropic followed responsible disclosure procedures throughout, consulting academics to validate findings and briefing US government and industry partners on the implications before public release.
💬 Discussion
Sign in to join the discussion.
Sign in →No comments yet — be the first.