AI cracked quantum-safe cryptography in 60 hours – humans searched for two years
Anthropic's Claude Mythos found a hidden weakness in the HAWK scheme – a US federal standards candidate – and invented an entirely new attack technique against weakened AES. Experts reassure: no real-world data is at risk.
AI company Anthropic disclosed on Monday that an unreleased version of its most powerful model, Claude Mythos, has found two previously unknown attacks on cryptographic algorithms. The most striking finding concerns HAWK – a digital signature scheme built to withstand future quantum computers, and a candidate to become a US federal standard.
Human cryptographers had scrutinised HAWK for roughly two years without finding the weakness. The AI model needed about 60 hours.
67 million times easier
The model found a mathematical symmetry in the scheme’s internal structure that no published analysis had exploited. For the scheme’s smallest configuration, HAWK-256, the cost of recovering a secret key fell from roughly 264 computational operations to about 238 – approximately 67 million times less work.
The model also invented an entirely new attack technique, dubbed the "Möbius Bridge", which makes a known attack on a deliberately weakened research variant of the AES encryption standard between 200 and 800 times faster. Both findings were checked and confirmed by human cryptographers before publication.
No cause for panic
Experts stress that no real-world data is at risk: HAWK has not yet been deployed anywhere, and the AES variant that was attacked is a weakened research version – not the full cipher protecting online banking, messaging services and hard drives around the world.
What is remarkable is not what was broken, but who broke it. Cryptanalysis – the art of finding shortcuts through the mathematics of encryption – has until now been the preserve of a small group of specialists. That an AI model independently found an original, verifiable mathematical weakness the field had overlooked for two years is considered a milestone for what AI systems can achieve in research.
The race for quantum-safe cryptography
The finding lands in the middle of a global transition: the world’s IT systems are switching to so-called post-quantum cryptography, designed to withstand attacks from future quantum computers. The new schemes are young, however, and far less thoroughly analysed than today’s standards – and that is precisely where AI-driven analysis can make the biggest difference, both for researchers wanting to plug holes before deployment, and eventually for attackers.
Anthropic published the findings on its research blog on July 28, following what the company describes as responsible disclosure to the affected research communities. The HAWK team will now likely have to adjust the scheme’s parameters – a far cheaper exercise now than after the standard had been deployed.