{"id":122802,"date":"2026-07-29T13:18:12","date_gmt":"2026-07-29T13:18:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/122802\/"},"modified":"2026-07-29T13:18:12","modified_gmt":"2026-07-29T13:18:12","slug":"anthropics-claude-mythos-preview-slashes-security-of-nist-post-quantum-candidate-hawk-and-finds-faster-aes-attack-biggo-finance","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/122802\/","title":{"rendered":"Anthropic\u2019s Claude Mythos Preview Slashes Security of NIST Post-Quantum Candidate HAWK and Finds Faster AES Attack \u2014 BigGo Finance"},"content":{"rendered":"<p>Anthropic\u2019s advanced artificial intelligence model, Claude Mythos Preview, has uncovered novel cryptographic attacks, including a key-recovery method against a leading post-quantum digital signature scheme and a dramatically faster assault on a reduced-round version of the Advanced Encryption Standard (AES). The findings, published by Anthropic on July 28, 2026, mark a significant acceleration in AI-driven cryptanalysis, with one attack cutting the security of the NIST candidate HAWK-256 by roughly 67 million times in computational effort.<\/p>\n<p>The AI operated largely autonomously, requiring only high-level project direction and final verification from human researchers. While neither discovery compromises currently deployed systems, the speed and sophistication of Claude Mythos Preview have intensified debate over whether AI is poised to outpace human expertise in securing the internet\u2019s foundational cryptography. Anthropic estimates the API cost for each of the two main research runs at approximately $100,000.<\/p>\n<p>Claude Mythos Preview developed an end-to-end key-recovery attack against HAWK-256, a post-quantum digital signature scheme that the National Institute of Standards and Technology (NIST) advanced to the third round of its additional signature competition in May 2026. HAWK is the sole remaining lattice-based candidate in that process. The AI discovered a previously unused automorphism\u2014a symmetry preserving the lattice structure underlying the scheme\u2014that reduces the key-recovery problem to finding a short vector in a lattice of roughly half the original dimension.<\/p>\n<p>Anthropic reported that the expected work factor for recovering a HAWK-256 secret key dropped from 2\u2076\u2074 operations to 2\u00b3\u2078, a reduction that makes the attack practical. The company released a public implementation that recovers a functionally equivalent signing key for HAWK-256 in about 3 hours and 42 minutes on a 96-core server. For the larger NIST security-level parameters, the gate-count estimates fell from 2\u00b9\u2075\u2070 to 2\u00b9\u2070\u2078 for HAWK-512 and from 2\u00b2\u2078\u2078 to 2\u00b9\u2078\u00b2 for HAWK-1024, both still impractical to attack.<\/p>\n<p>\u201cThe majority of mathematical discoveries in this paper were AI-assisted. Human author contribution mainly consisted of directing, organizing and verifying AI work,\u201d the researchers wrote in the HAWK paper. A human researcher who was not a lattice-cryptography specialist provided occasional project-management guidance. The attack exploits a \u03c4-cocycle lattice constructed from the public key and uses lattice reduction and sieving to recover short vectors before reconstructing a secret basis capable of signing messages.<\/p>\n<p>Anthropic noted that fixing the vulnerability would require roughly doubling HAWK\u2019s key sizes. \u201cUnfortunately, doubling HAWK\u2019s key size eliminates many of the reasons making the scheme an attractive PQC signature candidate,\u201d the company wrote. HAWK\u2019s compact signatures and fast signing were its primary selling points, particularly for blockchain applications where signature size directly affects transaction fees.<\/p>\n<p>In a separate effort, Claude Mythos Preview devised what Anthropic calls the \u201cM\u00f6bius Bridge,\u201d a mathematical invariant that speeds up a meet-in-the-middle attack on a seven-round version of AES-128 by a factor of 200 to 800. Full AES-128 uses ten rounds; studying reduced-round variants is standard practice for measuring the safety margin of a cipher.<\/p>\n<p>The AI\u2019s innovation removes a 256-way guessing step that was previously required, after researchers barred it from using five established families of AES cryptanalysis and instructed it to invent a sixth. Claude initially refused, insisting that \u201cthere\u2019s nothing easy to find; this is the most-studied block cipher in existence.\u201d After Anthropic researchers sent blunt encouragement over three days, the model produced the M\u00f6bius Bridge concept, then refined it over several more days, ultimately generating roughly one billion output tokens.<\/p>\n<p>The attack still requires an adversary to obtain about 2\u00b9\u2070\u2075 chosen plaintexts encrypted under a fixed, unknown key\u2014an assumption that places it far beyond real-world feasibility. Anthropic\u2019s released artifact performs component measurements and projects the complete attack\u2019s cost but does not execute a full AES-128 recovery from beginning to end.<\/p>\n<p>The company also disclosed a third finding that received less attention: Claude broke 13 rounds of LEA, a South Korean national standard and ISO lightweight-encryption standard used in phones and IoT devices, in under an hour on a desktop. The deployed LEA uses 24 rounds, so no fielded system is broken, but the prior best attack required 2\u2079\u2078 plaintext pairs.<\/p>\n<p>These disclosures follow the July 20 release of CryptanalysisBench, a 191-task benchmark developed by researchers from ETH Zurich, Anthropic, the University of Haifa, Technische Universit\u00e4t Berlin, and Tel Aviv University. Claude Mythos 5, described as the latest update to Mythos Preview, broke 85.7% of tasks with known solutions, compared with 65.3% for the weakest model tested. Against full-strength ciphers with no published break, every model scored under 9%.<\/p>\n<p>The results have immediate implications for the post-quantum standardization process. As of July 29, 2026, NIST continued to list HAWK as a third-round candidate, and it remains unclear whether the scheme\u2019s parameters, security claims, or standing will change. Anthropic disclosed both results to the algorithms\u2019 authors, U.S. government and industry partners, and coordinated the HAWK finding with NIST. The company thanked the HAWK team for helping verify the result.<\/p>\n<p>For Bitcoin and other cryptocurrencies, the research pokes at a longstanding concern: what happens when computers powerful enough to break the Elliptic Curve Digital Signature Algorithm (ECDSA) finally exist? Bitcoin currently relies on ECDSA, which would be vulnerable to a sufficiently large quantum computer. Analysts estimate roughly 6.7 million BTC\u2014around $600 billion\u2014sit in wallets exposed to such a machine. Bitcoin developers have already drafted BIP-361 to move coins onto quantum-resistant signatures, and NIST finalized its first post-quantum standards in 2024.<\/p>\n<p>The speed of AI-driven cryptanalysis is also reshaping the human role in security research. Anthropic warned that the cybersecurity community is grappling with the fact that language models can discover so many bugs that standard human processes for triage, verification, and remediation struggle to keep up. Two researchers spent nearly a month verifying the AES result, making human verification the visible bottleneck. \u201cIn just one year, language models have gone from being unable to perform cryptanalysis of even the most basic ciphers to being capable of finding flaws in cryptographic designs that have escaped discovery despite years of human expert review,\u201d Anthropic wrote.<\/p>\n<p>The findings have drawn attention from national security circles. Reports suggest the U.S. National Security Agency may be evaluating Claude Mythos for offensive cyber operations, raising questions about the dual-use nature of AI-driven cryptanalysis. Anthropic has limited distribution of Mythos to vetted enterprise partners and critical infrastructure organizations, with pricing starting at $10 per million input tokens and $50 per million output tokens.<\/p>\n","protected":false},"excerpt":{"rendered":"Anthropic\u2019s advanced artificial intelligence model, Claude Mythos Preview, has uncovered novel cryptographic attacks, including a key-recovery method against&hellip;\n","protected":false},"author":2,"featured_media":122803,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[61957,53,8263,529,61959,61961,17307,61960,61958,26257,17349],"class_list":["post-122802","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-advanced-encryption-standard-aes","tag-anthropic","tag-bitcoin","tag-claude-mythos-preview","tag-cryptanalysisbench","tag-ecdsa","tag-hawk","tag-lea","tag-mobius-bridge","tag-national-institute-of-standards-and-technology-nist","tag-post-quantum-cryptography"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122802","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=122802"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122802\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/122803"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=122802"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=122802"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=122802"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}