Anthropic's Claude Mythos Preview Discovers New Attacks on AES Encryption and Post-Quantum Signature Scheme HAWK
Anthropic's Claude Mythos Preview model independently discovered a new cryptanalytic attack on a reduced version of AES-128 and improved an existing attack on the post-quantum signature scheme HAWK. Each research run cost roughly $100,000 in API fees, with human researchers largely limited to project management and verification.
Anthropic says its Claude Mythos Preview model discovered mathematical weaknesses in two cryptographic schemes, working largely on its own in a multi-agent system at an API cost of roughly $100,000 per finding.
According to Anthropic, the model developed an improved attack on HAWK, a candidate post-quantum signature scheme in the third round of NIST's standardization process, and a new attack on a reduced 7-round version of AES-128, the world's most widely used symmetric encryption standard. Anthropic states neither finding affects systems currently in production. The AES attack targets a weakened variant using 7 of the algorithm's full 10 rounds, and HAWK remains an unapproved candidate under review.
HAWK: 60 hours versus two years of human review
Human cryptographers had studied HAWK for more than two years without finding this particular weakness, Anthropic says. Mythos Preview identified an improved attack in 60 hours by exploiting a previously undetected symmetry in the mathematical lattice underlying HAWK's security. The discovery emerged from a multi-agent setup: one agent initially dismissed the approach as infeasible, while a second agent found a way to fully exploit it. The human researcher overseeing the project had a background in theoretical computer science but was not a lattice-cryptography specialist, and his role was mostly limited to project management, according to Anthropic. Total API costs for the run were about $100,000.
AES: a model that initially said no
For the AES task, a researcher built a scaffold allowing Claude to form and test hypotheses experimentally. Mythos Preview initially refused to pursue the problem, writing that "AES-128 r5/r6 is just genuinely hard" and that no improvement was possible without changing the target. After the researcher encouraged it to seek "genuinely novel ideas," the model began a three-day run generating several hundred million tokens (Anthropic states the run reached roughly 1 billion tokens total) while receiving only three substantive human prompts. The result was a new fingerprinting method Anthropic calls "Möbius Bridge," which eliminates one required attacker guess and improves on prior best-known attacks by a factor of 200 to 800. This run also cost approximately $100,000 in API fees. Human researchers, none of them cryptography experts, then spent several hundred hours verifying the results.
Disclosure and access
Anthropic shared both findings in advance with the U.S. government and industry partners and coordinated disclosure of the HAWK weakness with the scheme's original authors. Mythos Preview remains unavailable to the public. Alongside researchers from ETH Zurich, Tel Aviv University, and the University of Haifa, Anthropic also released CryptanalysisBench, a benchmark intended to let outside researchers systematically evaluate the cryptanalytic capabilities of language models.
What this means
These are Anthropic's claims, not independently verified by outside cryptographers at publication time, though the company says findings were validated by domain experts before disclosure. The results suggest frontier models can now conduct extended, semi-autonomous mathematical research—generating hundreds of millions of tokens over multi-day sessions with minimal human steering—and produce novel results in a field where progress has historically required years of specialized human expertise. The $100,000-per-finding cost and the model's initial refusal to pursue the AES problem both indicate this capability is neither cheap nor fully automatic yet. But as models like Mythos improve at long-horizon research tasks, cryptographic standards bodies like NIST may need to factor AI-assisted cryptanalysis into how quickly candidate schemes are vetted before deployment.
Related Articles
Shared Claude Chats Exposed to Search Engines Due to Missing noindex Tag
Thousands of shared Claude conversations were indexed by search engines after Anthropic's sharing feature omitted a noindex tag. Some exposed chats reportedly contained crypto keys and legal queries; Anthropic has since fixed the issue on Google, though Bing and Brave Search retained results longer.
Claude Opus 5 Scores 30.2% on ARC-AGI-3, Nearly 4x the Previous Record
Claude Opus 5 scored 30.2 percent on the ARC-AGI-3 benchmark, nearly four times the previous record of 7.8 percent set by OpenAI's GPT-5.6 Sol (Max). The ARC Prize team attributes the leap to genuinely stronger reasoning, though an independent test on a separate puzzle benchmark showed far smaller improvements.
Anthropic's Claude Opus 5 Hits 0% Prompt Injection Success Rate in Browser Agent Tests, With Defenses Enabled
Anthropic's system card for Claude Opus 5 reports a 0% prompt injection success rate across 129 browser agent test scenarios when Auto Mode is enabled. On Gray Swan's broader indirect prompt injection benchmark, Opus 5 posted a 2.0% attacker success rate after 15 attempts, the lowest among tested frontier models.
Claude Opus 5 Scores 61 on Intelligence Index, Beats Fable 5 on Cost Across Most Benchmarks
Anthropic's Claude Opus 5 posts a 61 on the Artificial Analysis Intelligence Index, narrowly beating Claude Fable 5 (60) and GPT-5.6 Sol (59) while costing less per task. The model leads in coding and knowledge-work benchmarks but shows a rising hallucination rate of 50 percent.
Comments
Loading...