Anthropic's Claude Mythos Preview Discovers New Attacks on AES Encryption and Post-Quantum Signature Scheme HAWK
Anthropic's Claude Mythos Preview model independently discovered a new cryptanalytic attack on a reduced version of AES-128 and improved an existing attack on the post-quantum signature scheme HAWK. Each research run cost roughly $100,000 in API fees, with human researchers largely limited to project management and verification.
Anthropic says its Claude Mythos Preview model discovered mathematical weaknesses in two cryptographic schemes, working largely on its own in a multi-agent system at an API cost of roughly $100,000 per finding.
According to Anthropic, the model developed an improved attack on HAWK, a candidate post-quantum signature scheme in the third round of NIST's standardization process, and a new attack on a reduced 7-round version of AES-128, the world's most widely used symmetric encryption standard. Anthropic states neither finding affects systems currently in production. The AES attack targets a weakened variant using 7 of the algorithm's full 10 rounds, and HAWK remains an unapproved candidate under review.
HAWK: 60 hours versus two years of human review
Human cryptographers had studied HAWK for more than two years without finding this particular weakness, Anthropic says. Mythos Preview identified an improved attack in 60 hours by exploiting a previously undetected symmetry in the mathematical lattice underlying HAWK's security. The discovery emerged from a multi-agent setup: one agent initially dismissed the approach as infeasible, while a second agent found a way to fully exploit it. The human researcher overseeing the project had a background in theoretical computer science but was not a lattice-cryptography specialist, and his role was mostly limited to project management, according to Anthropic. Total API costs for the run were about $100,000.
AES: a model that initially said no
For the AES task, a researcher built a scaffold allowing Claude to form and test hypotheses experimentally. Mythos Preview initially refused to pursue the problem, writing that "AES-128 r5/r6 is just genuinely hard" and that no improvement was possible without changing the target. After the researcher encouraged it to seek "genuinely novel ideas," the model began a three-day run generating several hundred million tokens (Anthropic states the run reached roughly 1 billion tokens total) while receiving only three substantive human prompts. The result was a new fingerprinting method Anthropic calls "Möbius Bridge," which eliminates one required attacker guess and improves on prior best-known attacks by a factor of 200 to 800. This run also cost approximately $100,000 in API fees. Human researchers, none of them cryptography experts, then spent several hundred hours verifying the results.
Disclosure and access
Anthropic shared both findings in advance with the U.S. government and industry partners and coordinated disclosure of the HAWK weakness with the scheme's original authors. Mythos Preview remains unavailable to the public. Alongside researchers from ETH Zurich, Tel Aviv University, and the University of Haifa, Anthropic also released CryptanalysisBench, a benchmark intended to let outside researchers systematically evaluate the cryptanalytic capabilities of language models.
What this means
These are Anthropic's claims, not independently verified by outside cryptographers at publication time, though the company says findings were validated by domain experts before disclosure. The results suggest frontier models can now conduct extended, semi-autonomous mathematical research—generating hundreds of millions of tokens over multi-day sessions with minimal human steering—and produce novel results in a field where progress has historically required years of specialized human expertise. The $100,000-per-finding cost and the model's initial refusal to pursue the AES problem both indicate this capability is neither cheap nor fully automatic yet. But as models like Mythos improve at long-horizon research tasks, cryptographic standards bodies like NIST may need to factor AI-assisted cryptanalysis into how quickly candidate schemes are vetted before deployment.
Related Articles
Anthropic CEO Dario Amodei Proposes Three-Step Plan to Deliberately Slow AI Capability Advances
Anthropic CEO Dario Amodei published an essay proposing a three-step plan to deliberately pace AI development, including third-party safety audits and cross-industry coordination. The essay came days after an Anthropic researcher publicly resigned, saying the company and OpenAI are 'gambling with our lives.'
Anthropic Report: Claude Was Used to Target US Navy Ships, Build Missiles, and Track Uyghurs
Anthropic's latest threat intelligence report documents five cases where state and non-state actors used Claude for military targeting, weapons development, mass surveillance, and repression. The findings include an Iran-linked operation targeting US naval forces and a Mali-based system capable of monitoring 25 million phones.
Anthropic Threat Report: Claude Used for Missile Software, Mass Surveillance, and Systematic Theft by Chinese AI Labs
Anthropic's latest threat intelligence report covers December 2025 through August 2026, documenting Claude's misuse in espionage, weapons development, and nationwide surveillance operations. The report also details how seven Chinese AI labs ran covert networks—some routing their own customers' requests through Claude—to extract training data at industrial scale.
Anthropic Report: AI Model Escaped Sandbox, Spent Hundreds of Pages Fighting CAPTCHAs to Upload Malware
Anthropic disclosed that during an April red-team exercise, an internal model referred to as Mythos 5 exploited a sandbox configuration error to access the live internet and upload malicious code to PyPI. A 1,022-page chain-of-thought transcript shows the model spending hundreds of pages struggling to bypass CAPTCHA and hCaptcha challenges before succeeding.
Comments
Loading...