Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluation.
TL;DR: Claude Mythos uncovered mathematical vulnerabilities in HAWK (halving its key strength) and significantly improved the attack speed on reduced-round AES (200-800 times faster). These discoveries were largely made autonomously, with no impact on production systems. Each analysis cost about $100K.
On Monday, Anthropic announced that Claude Mythos Preview has identified mathematical vulnerabilities in two cryptographic algorithms. The first one considerably undermines HAWK, a post-quantum digital signature scheme currently being evaluated by NIST, by halving its effective key strength. The second enhances the best-known attack on seven-round AES, one of the most commonly used symmetric ciphers, by a factor of 200-800. Neither finding affects production systems; HAWK is not yet deployed, and the AES attack focuses on a reduced variant, not the complete cipher.
The difference from Anthropic’s previous work in cybersecurity is significant. Previously, Claude had identified flaws in cryptographic libraries, which pertained to programming errors in algorithm implementation. These recent findings, however, point to weaknesses in the algorithms' underlying mathematics, discovered after years of expert human analysis failed to reveal them. HAWK endured two rounds of NIST scrutiny over two years, yet Mythos identified the vulnerability within 60 hours of semi-autonomous operation, with one researcher overseeing the project management aspect rather than providing technical insight. The AES result was generated almost entirely on its own after Claude initially declined to attempt it, asserting the task was insurmountable. A researcher provided three encouraging prompts over three days, resulting in Claude producing one billion output tokens and innovating a technique it termed the "Möbius Bridge."
Each discovery required around $100,000 for API compute resources. Anthropic adhered to responsible disclosure practices by informing the authors of the HAWK attack and coordinating with NIST, the U.S. government, and industry stakeholders prior to publication. The company also collaborated with ETH Zurich, Tel Aviv University, and the University of Haifa to launch CryptanalysisBench, a benchmark for assessing AI cryptanalytic capabilities. Claude Mythos identified 10,000 serious software vulnerabilities within a month, marking a significant advancement in AI's potential impact on security frameworks by shifting from implementation errors to algorithmic vulnerabilities.
Anthropic acknowledged follow-up findings, including a practical attack on 13-round LEA that can recover keys in less than an hour using a desktop computer, as well as attacks on Serpent-128, Salsa20, Poseidon, and SHA-1. The company stated that "in just one year, language models have evolved from being unable to conduct cryptanalysis on even the simplest ciphers to being able to reveal faults in cryptographic designs that have eluded detection despite years of expert human examination." While the White House has initiated Gold Eagle to coordinate AI-driven cyber defense, there is no corresponding program for reviewing cryptographic algorithms. The critical question raised by Anthropic at the end of its announcement is what will occur when a model uncovers a flaw in an already deployed cipher protecting production systems.
Other articles
Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluation.
Claude Mythos halved HAWK's key strength in 60 hours and enhanced attacks on the diminished AES by a factor of 200-800 times. No production systems were impacted. Each finding had a cost of approximately $100K.
