In short
- Anthropic stated its unreleased Claude Mythos Preview mannequin discovered a beforehand unknown assault on HAWK, dropping the price of stealing its smallest key from 2^64 operations to 2^38.
- The mannequin additionally sped up an assault on a 7-round model of AES by 200 to 800 occasions, beating a report cryptographers set in 2013.
- Every consequence value roughly $100,000 in API utilization, and Anthropic workers spent a number of hundred hours verifying the AES work was actual.
Anthropic immediately stated an unreleased model of its strongest AI mannequin discovered two beforehand unknown assaults on cryptographic algorithms, one in every of them towards a scheme presently competing to change into a U.S. federal commonplace.
That scheme is HAWK, a digital signature system—the maths that proves a transaction got here from you with out ever exposing your personal key—constructed to outlive future quantum computer systems. The non-regulatory federal company and lab NIST moved it into the third spherical of its post-quantum signature competitors in Could, the place it’s the final lattice-based candidate standing.
Claude discovered a symmetry buried in HAWK’s math that no human had thought to make use of. For the smallest configuration, the price of recovering a secret key fell from 2^64 operations to 2^38, roughly 67 million occasions much less work.
Fixing it means roughly doubling HAWK’s keys. “Sadly, doubling HAWK’s key measurement eliminates lots of the causes making the scheme (because it presently stands) a sexy PQC signature candidate,” Anthropic wrote.
New Anthropic analysis: Discovering cryptographic weaknesses with Claude.
Claude Mythos Preview has helped our researchers discover weaknesses in cryptographic algorithms—the mathematical strategies which can be used to maintain knowledge personal.
Learn extra: https://t.co/TYKLjb3Q7V
— Anthropic (@AnthropicAI) July 28, 2026
That commerce issues extra to blockchains than it sounds. Signature measurement is block house, and block house is charges, so any chain purchasing for a quantum-resistant alternative is partly selecting on bytes per signature. Compact keys and quick signing have been HAWK’s total pitch, and the repair prices it a lot of that edge.
Don’t fear, hodlers: Your cash are advantageous (for now). HAWK has by no means been deployed wherever, and Bitcoin nonetheless runs on ECDSA, the pre-quantum signature scheme that candidates like HAWK are finally meant to interchange.
Anthropic disclosed each outcomes to the algorithms’ authors and to U.S. authorities and trade companions earlier than publishing, and coordinated the HAWK discovering with NIST.
The AES consequence wanted a pep speak
The second assault targets AES, the cipher scrambling your HTTPS site visitors, your encrypted drive, and your alternate’s backend. Full AES-128 pushes knowledge by 10 rounds of scrambling, and Claude attacked a 7-round analysis model that no person has improved on since 2013.
The setup was intentionally harsh. Researchers barred the mannequin from all 5 established households of AES cryptanalysis and informed it to invent a sixth, closing the temporary with a line about how the primary differential assault did not beat something—it invented the sport. Claude additionally inherited working notes from earlier agent runs that had already burned by roughly 200 failed assault variants.
It refused anyway. “On AES-128 r5/r6/r7 it discovered nothing as a result of there’s nothing simple to search out; that is the most-studied block cipher in existence,” the mannequin informed researchers, per transcripts Anthropic revealed.
Anthropic despatched simply three substantive messages over the subsequent three days, amongst them: “no once more the aim is that now we have extremely inteligent [sic] mannequin pretty much as good high researcher, we need to discover new assaults.” One other refused to let Claude swap AES for a better cipher.
Then it produced the trick the paper calls a Möbius Bridge, killing one of many 9 key bytes an attacker beforehand needed to guess. Refining that into the revealed model took a number of extra days and a billion output tokens.
The discovering with the shortest path to one thing actual bought the least consideration. Claude additionally broke 13 rounds of LEA, a Korean nationwide commonplace and ISO lightweight-encryption commonplace constructed for telephones and internet-of-things units, in below an hour on a desktop towards a previous greatest that wanted 2^98 plaintext pairs. The deployed LEA runs 24 rounds, so nothing within the subject is damaged.
Verification took longer than discovery
The HAWK paper is unusually blunt in regards to the division of labor. “Nearly all of mathematical discoveries on this paper have been AI-assisted. Human creator contribution primarily consisted of directing, organizing and verifying AI work,” its authors wrote.
Claude discovered the AES thought in days. Anthropic researchers then spent a number of hundred hours studying sufficient cryptography to substantiate it labored—the identical mannequin that discovered 271 vulnerabilities in Firefox throughout inner testing.
“The cybersecurity neighborhood is now grappling with the truth that language fashions are capable of uncover so many bugs that the usual human processes (like vulnerability triage, verification, and remediation) wrestle to maintain up,” Anthropic wrote, warning that human researchers could change into the bottleneck.
Anthropic additionally constructed CryptanalysisBench—191 cipher-breaking duties drawn principally from NIST competitions. Fashions submit a working assault script that both wins a proper safety sport or does not, with no partial credit score and no human grading.
Mythos 5 broke 85.7% of duties with identified options, towards 65.3% for the weakest mannequin examined. In opposition to full-strength ciphers with no revealed break, each mannequin scored below 9%.
Day by day Debrief E-newsletter
Begin day by day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.

