Crypto

Claude Mythos cryptography tests found new attacks, Anthropic says

Anthropic says Claude Mythos Preview found weaknesses in HAWK and a 7-round AES test, raising questions for post-quantum security.

Theo Nakamura

By Theo Nakamura · Staff Writer

· 3 min read

Claude Mythos cryptography tests found new attacks, Anthropic says
Photo: Decrypt

Anthropic says its unreleased Claude Mythos cryptography work has produced two new attacks on encryption-related systems, including one aimed at HAWK, a post-quantum digital signature candidate under review for a possible U.S. federal standard. For crypto investors, the headline is less about coins being at risk today and more about how future blockchain security choices may be tested by AI.

The company said Claude Mythos Preview, an unreleased version of its strongest model, identified a weakness in HAWK that cut the work needed to recover the smallest secret key from 2^64 operations to 2^38. Anthropic described that as roughly 67 million times less work.

HAWK is a digital signature scheme, meaning it is designed to prove that a message or transaction was authorized by a private key without revealing that key. It is built for a post-quantum world, where future quantum computers could threaten some of the cryptography used today.

The National Institute of Standards and Technology, or NIST, moved HAWK into the third round of its post-quantum signature competition in May, according to Anthropic. The company said HAWK is the last lattice-based candidate still in that round.

Did Claude Mythos break post-quantum cryptography?

Anthropic did not say Claude broke a live crypto network or a deployed standard. The HAWK issue affects a candidate system that Anthropic said has not been deployed, and the company said the practical fix would be to roughly double HAWK’s key sizes.

That fix matters because size is part of the product. In blockchains, signatures take up block space, and block space affects fees. Anthropic said larger HAWK keys would remove many of the advantages that made the scheme attractive as a post-quantum signature candidate.

Anthropic said it shared the findings with the algorithms’ authors and with U.S. government and industry partners before publication. The company also said it coordinated the HAWK disclosure with NIST.

What happened with AES?

Anthropic said Claude Mythos Preview also found a faster attack on a research version of AES, the widely used cipher behind systems such as encrypted web traffic, encrypted drives and exchange infrastructure. AES-128 uses 10 rounds of scrambling, while the attack involved a 7-round version used in cryptography research.

According to Anthropic, the model improved an attack on that 7-round AES setup by 200 to 800 times. The company said the previous record had stood since 2013.

That distinction is important for everyday users: Anthropic described the AES result as an attack on a reduced-round research version, not on full AES-128. Reduced-round tests are a standard way for cryptographers to study whether ideas could eventually matter for the full system.

Anthropic said each result cost about $100,000 in API usage. The company also said its staff spent several hundred hours checking the AES result before concluding that it was valid.

The broader takeaway is that advanced AI models are starting to act less like coding assistants and more like research partners in technical fields. In cryptography, that could mean faster discovery of weaknesses before systems are widely adopted, while also raising the stakes for careful verification by human experts.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto