Claude discovers vulnerabilities in encryption algorithms, attacking HAWK and a reduced version of AES
Listen to this article
Read by Anchor
In Anthropic's labs, the Claude Mythos Preview model achieved what human cryptographers had failed to do over two years: improving the best-known attack on the HAWK digital signature scheme, one of the final candidates in the National Institute of Standards and Technology (NIST) competition for post-quantum systems, and cutting its cryptographic power in half, all in just 60 working hours.
The second result is no less significant: the model discovered a new way to break a reduced-round version of the Advanced Encryption Standard (AES), the most widely used symmetric encryption in the world, achieving a speedup of between 200 and 800 times compared to the best previous attacks, by eliminating one of the guesses an attacker would have had to make.
The vital context:HAWK entered the third round of NIST's evaluation of quantum-resistant digital signature systems after withstanding two rounds of specialized human review. AES, for its part, has been approved since 2001 and is a cornerstone for securing banking communications, secure browsing (HTTPS), and sensitive data storage. The discoveries do not threaten current production systems: HAWK is a unapplied candidate, and the attack on AES targets a reduced version, but they demonstrate that advanced artificial intelligence models are now capable of making serious contributions to cryptographic strength analysis, before and after publication.
How the discovery was made:One researcher at Anthropic worked with Mythos for a week to develop the HAWK attack, and another built a 'scaffold' that allowed the model to discover the AES attack entirely on its own. The cost of each result was around $100,000 in API costs. In collaboration with researchers from the Swiss Federal Institute of Technology in Zurich (ETH Zurich), Tel Aviv University, and the University of Haifa, Anthropic launched the CryptanalysisBench standard to evaluate models' abilities to analyze cryptography, and published the full technical papers: HAWK key recovery, the Möbius strip for AES, and the model's thought process in the second case.
What this means for digital sovereignty:The region is investing billions in digital infrastructure: central banks, digital identities, government communications, energy networks. The cryptographic strength that protects these assets is no longer tested by humans alone; artificial intelligence models have become a party in the cryptographic arms race. Countries building their digital sovereignty need three things: first, to follow cryptographic analysis research with artificial intelligence as part of risk assessment. Second, to contribute to regional post-quantum standards rather than passively waiting. Third, to understand that 'security through obscurity' is no longer sufficient when an independent model can explore the attack space faster than human teams.
International standards are already moving: NIST has begun studying how to integrate artificial intelligence robustness tests into the evaluation processes of post-quantum candidates. Regulatory bodies in the region, from communications authorities to central banks, are required to closely follow this shift. Ignoring the ability of models to analyze cryptography means accepting uncalculated risks in the systems being built today and serving for decades.
The practical summary:Regulatory and security bodies in the region are required to include 'artificial intelligence robustness testing' in the standards for approving sensitive cryptographic systems. International standards (NIST, ISO) will in turn begin to take this dimension into account. The initiative now, by forming joint teams of cryptographers and artificial intelligence engineers, provides a time window before cryptographic analysis with artificial intelligence becomes a common capability among adversaries.