Anthropic says Claude found new cryptographic weaknesses
Anthropic says Claude Mythos Preview found new attacks on the HAWK post-quantum signature scheme and a reduced-round version of AES. Neither result breaks deployed crypto, but both show frontier models can contribute to mathematical cryptanalysis.
TL;DR: Anthropic says Claude Mythos Preview found improved attacks on two cryptographic targets: the HAWK post-quantum signature scheme and a weakened 7-round version of AES. Neither result breaks deployed production crypto today, but both show frontier models can contribute to mathematical cryptanalysis, not just code auditing.
Key Takeaways
- Anthropic says Claude Mythos Preview found a faster enumeration attack on HAWK that 'effectively halves' the scheme's effective key size — researchers say doubling key sizes would erase most of HAWK's appeal as a post-quantum candidate.
- A separate Claude-built 'Möbius Bridge' algorithm yielded a 200-800x speedup over earlier attacks on 7-round AES-128. Anthropic published a Mythos-edited chain-of-thought document for the result.
- Each result reportedly cost about $100,000 in API spend and hundreds of hours of researcher validation time — useful capability, but not yet cheap, push-button offensive.
- Anthropic partnered with ETH Zurich, Tel Aviv University, and TU Berlin on CryptanalysisBench, signaling that LLM cryptanalysis is moving from one-off demos to repeatable benchmarks.
Research result
The headline is not "AI broke encryption." It's narrower, and still important: Anthropic researchers report that Claude helped discover new weaknesses in two cryptographic constructions under active academic study.
The first target was HAWK, a third-round candidate in NIST's process for additional post-quantum digital signatures. The second was a round-reduced version of AES-128, where the team studied 7 rounds instead of the full 10 used in practice.
That distinction matters. HAWK is not deployed production infrastructure. The AES result does not apply to standard AES-128 as used today. Anthropic is explicit on both points, and readers should keep them front and center.
HAWK weakness
The more consequential result is HAWK. Anthropic says Mythos found a nontrivial automorphism in HAWK's lattice structure that enables a faster enumeration attack.
The claimed impact is severe for the scheme's positioning: HAWK's effective key size is "effectively halved." If that analysis holds, maintaining the same security level would require doubling key sizes, which would erase much of HAWK's appeal as a post-quantum candidate.
The process is notable. Anthropic says the discovery took about 60 hours of semi-autonomous work in a multi-agent harness and around $100,000 in API spend. The human operator had a theoretical computer science background but was not a lattice cryptography specialist. Their role was mostly project management rather than doing the attack by hand.
The key idea reportedly came from two Mythos agents working together. That detail matters because it suggests orchestration, not just raw model quality, is part of the capability.
Anthropic says it shared the finding with HAWK's authors in June and coordinated public disclosure.
AES result
The AES result is less immediately alarming but still technically interesting. Anthropic focused on 7-round AES-128, a weakened version used in research rather than real-world deployments.
Claude developed what Anthropic calls the "Möbius Bridge" fingerprinting algorithm, extending prior work. The reported gain is large: a 200-800x speedup over earlier attacks, depending on parameters.
Here the workflow differed. A researcher built a scaffold that let Claude generate hypotheses and run experiments autonomously. Anthropic says Claude initially concluded the problem was impossible. After being prompted to keep trying, it found the Möbius Bridge idea three days later and spent the next several days refining it.
The cost was again about $100,000 in API usage, plus hundreds of hours of researcher time to validate the claims and prepare the paper. That last part is easy to miss. Model output was not self-certifying; humans still had to do substantial verification work.
Anthropic also released a Mythos-edited chain-of-thought document for this result, which is unusual and signals confidence in the research process.
Capability signal
The deeper signal is that frontier models are starting to contribute to mathematical security research, not just implementation-level bug finding.
That is a step up in difficulty. Finding memory safety issues in code or misconfigurations in cloud systems is one thing. Identifying exploitable structure in lattices or improving cryptanalytic techniques against reduced-round ciphers is another.
Still, this is not yet cheap, push-button offensive capability. Anthropic's own numbers put each result at roughly $100,000 in API cost, with significant human supervision and validation. For now, that keeps the bar high enough that only large labs, governments, or well-funded organizations can reproduce this kind of work at scale.
But cost curves matter. If the same workflows get 10x cheaper, or if model quality improves enough to cut researcher oversight, the audience expands fast.
Workflow signal
The HAWK and AES cases point to a practical lesson: scaffolding matters.
In HAWK, Anthropic highlights a multi-agent setup where paired agents produced the key idea. In AES, the model needed a scaffold for autonomous hypothesis generation and experimentation, plus a human nudge after an initial false negative.
That means teams evaluating frontier models for security work should pay less attention to benchmark screenshots and more attention to systems design: decomposition, agent interaction, experiment loops, and verification. The model alone was not the product. The harness was part of the result.
Anthropic also partnered with ETH Zurich, Tel Aviv University, and TU Berlin on CryptanalysisBench, a benchmark for LLM cryptanalytic capability. That suggests this will move from one-off demo papers toward repeatable evaluation.
Risk boundary
The source here is strong on novelty but thin on ecosystem-wide impact beyond these two results. Anthropic has shown two case studies, not a general proof that LLMs can rapidly break modern deployed cryptography.
Even so, the direction is hard to ignore. Corporate migration cycles in security are slow. Post-quantum transitions are already expensive and politically messy. If AI-assisted offense improves faster than defensive review, candidate schemes and niche deployments could face pressure before organizations are ready to respond.
Anthropic says it shared advance copies with US government and industry partners. That is standard responsible behavior, but it also underscores who is currently positioned to act on this kind of capability: institutions with budget, compute, and specialist reviewers.
Builder response
Builders should treat this as a planning signal, not a panic event. If you build in security, assume advanced model-assisted cryptanalysis will get cheaper and more common; budget for external review of bespoke crypto, avoid inventing your own schemes, and track post-quantum candidates with more skepticism about "paper security" claims. If you build AI systems, invest in scaffolds that can generate hypotheses, run experiments, and verify outputs, because the value here came from orchestration plus validation, not one-shot prompting.
Sources
- [1]Claude's cryptographic research findings (HAWK and AES) — Anthropic (2026-07-29)
- [2]CryptanalysisBench: evaluating LLM cryptanalytic capability — ETH Zurich / Tel Aviv University / TU Berlin (2026-07-29)
- [3]HAWK signature scheme specification — HAWK team (2024-10-09)
Get the next briefing
Signal-first AI briefings, weekday mornings.
One concise briefing with three signals, why they matter, and one action to take.
Free. No spam. Unsubscribe anytime. · Weekday mornings.
Share this article