The gist: Anthropic has used Claude Mythos to develop a practically inapplicable but academically relevant attack on AES variants and an improved attack on the post-quantum candidate Hawk.
Anthropic has used the Claude Mythos model to discover ways to accelerate attacks against two cryptographic algorithms — including the NIST candidate Hawk for post-quantum signatures. The findings do not impact productive systems, but reveal weaknesses in security margins.
Anthropic’s Claude Mythos preview model has demonstrated methods for accelerating attacks against two cryptographic algorithms. Hawk is a candidate procedure for digital signatures in the post-quantum domain, currently being evaluated by the US National Institute of Standards and Technology (NIST). The second attack targets reduced variants of the Advanced Encryption Standard (AES).
For Hawk, Mythos was able to improve the previously known attack in just 60 hours — despite two rounds of expert peer review over two years. Anthropic examined only the 256-bit version of Hawk, while NIST is evaluating the 512- and 1024-bit versions. Nevertheless, the result is relevant: the key sizes proposed in the NIST submission prove to be significantly weaker than originally assumed. While Hawk remains practically invulnerable with larger keys, the improved attack effectively halves the security level and would require considerably longer keys. This would consume many of the efficiency advantages that made Hawk attractive as a post-quantum candidate. Anthropic emphasizes that the result is specific to Hawk and is not generalizable to other NIST post-quantum candidates or lattice-based cryptography in general.
The second attack employs a new cryptoanalytic technique called “Mobius Bridge” against reduced AES-128 variants with only seven rounds instead of the full ten. This new method accelerates previous attacks by a factor of 200 to 800, but remains far from a practical threat. The attack assumes a “chosen plaintext” scenario in which an attacker can encrypt approximately 2^105 (about 4 quadrillion) self-selected plaintexts — a completely unrealistic scenario for operationally deployed AES implementations.
Claude Mythos discovered the AES attack largely independently. An Anthropic researcher built a framework that enabled Claude to formulate hypotheses, validate them experimentally, and then design attacks itself. Such findings improve understanding of the security margins of modern cryptographic procedures — a standard practice for assessing the robustness of ciphers like AES.
Source: www.csoonline.com · Published 29 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.