Article is online

Anthropic’s Claude Mythos Uncovered New Cryptographic Attacks Previously Eluding Human Researchers

Anthropic’s Claude Mythos Uncovered New Cryptographic Attacks Previously Eluding Human Researchers

Table of Contents




You might want to know


1. Could advanced generative models routinely discover previously unknown weaknesses in modern cryptographic designs?


2. What are the downstream implications for standards, deployments, and the human processes that validate new cryptanalytic findings?



Main Topic


The recent announcements from Anthropic describe how an unreleased iteration of their Claude Mythos model identified two previously unknown cryptanalytic results: one affecting a post-quantum digital-signature candidate called HAWK, and another that accelerates an attack on a reduced-round version of AES. These findings illustrate how large-scale generative models can contribute to deep mathematical exploration and problem solving in fields like cryptanalysis, where discovery historically relied on teams of specialists working for extended periods.



HAWK is a lattice-based signature scheme that has been under evaluation as part of the ongoing post-quantum cryptography (PQC) standardization efforts. It was promoted for offering compact signatures and efficient signing operations, attributes that matter particularly in blockchain contexts where signature size directly impacts block space and fees. Anthropic reports that Claude discovered a structural symmetry in HAWK's mathematical construction that humans had not exploited. For HAWK's smallest parameter set, this insight reduces the estimated work to recover a private key from approximately 264 operations to about 238 operations — a reduction of roughly 226, or on the order of tens of millions in work factor. The practical countermeasure Anthropic proposes is increasing key sizes, which restores security margins but undermines the compactness that had made HAWK attractive for some use cases. As Anthropic notes, doubling HAWK’s keys removes much of the scheme’s prior appeal for applications sensitive to signature size.



Importantly, HAWK had not been deployed in production systems, and the discovery was coordinated with the scheme’s authors and standards bodies before public disclosure — Anthropic reports notifying algorithm designers, government partners, and NIST. This disclosure process reduced the risk of immediate practical exploitation and gave developers a chance to respond.



The second result concerns AES, the widely used symmetric cipher that protects much of today’s encrypted traffic and stored data. Full AES-128 applies ten rounds of nonlinear transforms and mixing; Anthropic’s team restricted the model to analyze a research variant with seven rounds. Claude purportedly produced an innovative attack technique referred to in their write-up as a Möbius Bridge, which removes the need to guess one of nine key bytes in the prior best approach. That improvement effectively accelerates an attack on AES-128 reduced to seven rounds by a factor reported between 200x and 800x compared to the previous published result. The researchers emphasize the constrained scope: the attack targeted fewer rounds than full AES-128 and was developed under rigorous constraints (models were blocked from using the five major established families of AES cryptanalysis), making the breakthrough notable in the research context but not an immediate threat to deployed AES.



Anthropic’s accounts emphasize the interaction between model outputs and human verification. In both investigations the AI produced candidate mathematical ideas rapidly; the human researchers subsequently invested substantial time confirming and formalizing those ideas. For the AES work, Anthropic says researchers spent several hundred hours learning sufficient cryptographic detail and verifying the model-suggested insight. This pattern — rapid model-driven idea generation followed by labor-intensive human validation — is a recurring theme: models can propose many novel directions, but humans remain essential for rigorous proof, error checking, and contextual judgment.



Anthropic also reports results from a broader evaluation suite called CryptanalysisBench, which comprises a set of cipher-breaking tasks drawn largely from public competitions. On tasks with known solutions, their best Mythos model solved about 85.7% of instances, while weaker models solved fewer. Against full-strength ciphers with no known published breaks, performance remained low. These benchmarks indicate models are capable of reproducing and sometimes improving on human discoveries in constrained research problems, but they are not yet a generic replacement for years of specialized cryptanalytic research across all cipher families.



The operational and policy implications are multifaceted. First, the discovery path highlights the value of coordinating disclosures: informing authors and standards bodies prevents accidental exposure and gives designers time to adjust parameters. Second, the results change how the community must think about verification workflows and triage: if models can propose many plausible vulnerabilities, the human bottleneck shifts from ideation to verification, requiring more trained reviewers, formal validation tools, and possibly automated proof-assistants. Third, the cryptographic community must reassess assumptions about what constitutes a secure parameter set; automated search guided by powerful models may reveal structural symmetries or shortcuts humans have missed, necessitating larger safety margins or alternative constructions.



Finally, these developments illustrate a broader research dynamic: machine-assisted mathematics and security research can accelerate discovery, but they also demand careful governance, reproducible verification, and transparent coordination with affected stakeholders. For applied fields such as cryptography, where theoretical advances can have far-reaching practical consequences, a conservative approach to disclosure and remediation remains essential.



Key Insights Table












AspectDescription
ModelAn unreleased Claude Mythos Preview identified novel cryptanalytic ideas.
HAWK impactReduced key-recovery cost for smallest parameters from 264 to 238; mitigation requires larger keys.
AES impactFound a new technique for 7-round AES, improving attack cost by ~200–800x over prior work; not a break of full AES-128.
VerificationAI produced ideas quickly; humans spent hundreds of hours verifying and formalizing results.
BenchmarksCryptanalysisBench showed improved performance on known tasks but limited success against full-strength, unbroken ciphers.
DisclosureFindings were coordinated with authors, NIST, and government partners before public disclosure.


Afterwards...


Looking forward, AI-assisted discovery is likely to become a regular feature of cryptographic research. That will require updated processes: better automated verification tools, increased investment in human expertise for triage and proof checking, and strengthened coordination protocols for responsible disclosure. Standards bodies may adopt more conservative parameter margins or adjust evaluation criteria to account for automated search techniques. For practitioners, the immediate takeaway is vigilance: no deployed system is reported broken by these results, but the landscape of cryptographic assurance is evolving. Organizations that design, standardize, or deploy cryptography should plan for more frequent, model-proposed discoveries and ensure they have the resources to validate, respond, and remediate quickly.



In short, Claude Mythos’ findings demonstrate both the promise and the operational challenge of integrating generative models into security research. The models can accelerate insight, but human-led verification, careful disclosure, and adaptive standards remain essential to maintain real-world security.


Last edited at:2026/7/28

Claude AI

AI Smart Editor