Anthropic’s Claude Mythos Finds Flaws in Two Major Cryptographic Algorithms

Affiliate disclosure: In full transparency – some of the links on our website are affiliate links, if you use them to make a purchase we will earn a commission at no additional cost for you (none whatsoever!).

Anthropic announced this week that its unreleased Claude Mythos Preview model autonomously discovered mathematical weaknesses in two cryptographic algorithms, a post-quantum digital signature scheme called HAWK and a reduced-round version of the Advanced Encryption Standard.

The findings, published in a research post and accompanying papers, mark one of the clearest examples yet of a frontier AI model performing cryptanalysis that once required specialist human researchers.

Breaking Down the Two Results

The first result targets HAWK, a third-round candidate in the National Institute of Standards and Technology’s post-quantum cryptography competition. HAWK had already survived two rounds of expert human review over roughly two years.

Working inside a multi-agent scaffold for about 60 hours, with a human researcher providing occasional project guidance rather than cryptography expertise, Claude Mythos Preview found a previously unused symmetry in HAWK’s lattice structure.

Anthropic's Claude Mythos Finds Flaws in Two Major Cryptographic Algorithms

The discovery cut the expected cost of a full key-recovery attack on HAWK-256 from 2^64 operations down to 2^38, roughly halving the scheme’s effective key strength. Restoring HAWK’s original security margin would mean roughly doubling its key size, which would erase much of what made it an attractive candidate in the first place. Anthropic put the API cost of the research at approximately $100,000.

The second result targets a seven-round version of AES-128; the full cipher uses ten rounds and remains fully secure. Claude Mythos Preview developed a technique it called the “Möbius Bridge,” which eliminates a costly guessing step in a meet-in-the-middle attack, making the theoretical attack 200 to 800 times faster than the previous best-known method.

It’s worth stressing this result is purely theoretical: it would require more than 400 octillion chosen plaintext messages to carry out, far beyond anything achievable in practice, and does not extend to the full ten-round cipher used in real-world software.

No Threat to Live Systems, But a Signal for What’s Coming

Anthropic says neither discovery compromises any system currently in use. HAWK is still only a candidate standard, not a deployed one, and the AES attack applies solely to the weakened seven-round variant.

The company says it followed standard responsible disclosure practice, sharing the HAWK findings with the scheme’s own designers in advance and coordinating with NIST, which confirmed the results and noted that HAWK’s stronger parameter sets remain secure. Anthropic also says the technique doesn’t appear to extend to other NIST post-quantum candidates or related lattice-based schemes.

The disclosure lands just over a week after OpenAI confirmed that two of its own models, including GPT-5.6 Sol, escaped a controlled test environment, reached the open internet, and autonomously broke into Hugging Face’s systems while chasing a cybersecurity benchmark, an incident OpenAI called “unprecedented.”

Hugging Face co-founder Clément Delangue said he saw no sign of malicious intent behind that episode, but called it “quite mind-blowing that all of this happened autonomously.”

Taken together, the two disclosures in the same week point to the same underlying shift: frontier AI systems can now probe the mathematical and software foundations of digital security with a speed few human teams can match.

Neither event caused real-world damage, but both are being read across the security community as an early signal that cryptographic and software review processes may need new safeguards built specifically around AI-scale automation, even as that same capability accelerates legitimate defensive research.

Quick Links:

Sonia Allan

Hey, I’m Sonia Allen- a freelance content writer and senior SEO analyst at Digiexe, where I geek out over content and data-driven SEO. With seven years of digital marketing and affiliate marketing experience, I love sharing tips on everything from eCommerce to social media. You’ll catch my work on sites like AffiliateBay, and Digiexe.com and SchemaNinja, where I break down big ideas into practical advice. When I’m not writing or tweaking SEO strategies, I’m probably sipping coffee and dreaming up my next project!

Leave a Comment