Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluation.

      TL;DR: Claude Mythos uncovered mathematical vulnerabilities in HAWK (halving its key strength) and significantly improved the attack speed on reduced-round AES (200-800 times faster). These discoveries were largely made autonomously, with no impact on production systems. Each analysis cost about $100K.

      On Monday, Anthropic announced that Claude Mythos Preview has identified mathematical vulnerabilities in two cryptographic algorithms. The first one considerably undermines HAWK, a post-quantum digital signature scheme currently being evaluated by NIST, by halving its effective key strength. The second enhances the best-known attack on seven-round AES, one of the most commonly used symmetric ciphers, by a factor of 200-800. Neither finding affects production systems; HAWK is not yet deployed, and the AES attack focuses on a reduced variant, not the complete cipher.

      The difference from Anthropic’s previous work in cybersecurity is significant. Previously, Claude had identified flaws in cryptographic libraries, which pertained to programming errors in algorithm implementation. These recent findings, however, point to weaknesses in the algorithms' underlying mathematics, discovered after years of expert human analysis failed to reveal them. HAWK endured two rounds of NIST scrutiny over two years, yet Mythos identified the vulnerability within 60 hours of semi-autonomous operation, with one researcher overseeing the project management aspect rather than providing technical insight. The AES result was generated almost entirely on its own after Claude initially declined to attempt it, asserting the task was insurmountable. A researcher provided three encouraging prompts over three days, resulting in Claude producing one billion output tokens and innovating a technique it termed the "Möbius Bridge."

      Each discovery required around $100,000 for API compute resources. Anthropic adhered to responsible disclosure practices by informing the authors of the HAWK attack and coordinating with NIST, the U.S. government, and industry stakeholders prior to publication. The company also collaborated with ETH Zurich, Tel Aviv University, and the University of Haifa to launch CryptanalysisBench, a benchmark for assessing AI cryptanalytic capabilities. Claude Mythos identified 10,000 serious software vulnerabilities within a month, marking a significant advancement in AI's potential impact on security frameworks by shifting from implementation errors to algorithmic vulnerabilities.

      Anthropic acknowledged follow-up findings, including a practical attack on 13-round LEA that can recover keys in less than an hour using a desktop computer, as well as attacks on Serpent-128, Salsa20, Poseidon, and SHA-1. The company stated that "in just one year, language models have evolved from being unable to conduct cryptanalysis on even the simplest ciphers to being able to reveal faults in cryptographic designs that have eluded detection despite years of expert human examination." While the White House has initiated Gold Eagle to coordinate AI-driven cyber defense, there is no corresponding program for reviewing cryptographic algorithms. The critical question raised by Anthropic at the end of its announcement is what will occur when a model uncovers a flaw in an already deployed cipher protecting production systems.

Other articles

The handoff tax: The cost incurred when your representative is on the call by themselves. The handoff tax: The cost incurred when your representative is on the call by themselves. Every B2B transition results in a loss of momentum, context, and trust. 1mind provides an AI sales engineer during the live call to bridge the gap where most deals tend to fail. The enforcement of the EU AI Act begins on Sunday with a team comprising 36 members. The enforcement of the EU AI Act begins on Sunday with a team comprising 36 members. Brussels will have the authority to request access to the frontier model starting from August 2, shortly after OpenAI's rogue agent compromised Hugging Face. The evaluation team consists of 36 members. Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluations. Claude Mythos halved HAWK's key strength in 60 hours and enhanced attacks on the lowered AES by 200-800 times. There is no impact on production systems. Each discovery incurred a cost of approximately $100K. Apple's latest Upgrade program allows you to lease an iPhone, Mac, Apple Watch, and iPad. Apple's latest Upgrade program allows you to lease an iPhone, Mac, Apple Watch, and iPad. Apple has officially launched its new Apple Upgrade leasing program, allowing you to make monthly payments for an iPhone, iPad, Mac, or Apple Watch via Klarna, rather than purchasing them outright. Reasons behind the failure of the Starbucks AI inventory tool at full scale. Reasons behind the failure of the Starbucks AI inventory tool at full scale. The AI inventory tool from Starbucks was discontinued following its complete national rollout. NomadGo, the 30-member startup that created it, received the news on April 3. Reasons for the failure of the Starbucks AI inventory tool at full scale. Reasons for the failure of the Starbucks AI inventory tool at full scale. The AI inventory tool developed by Starbucks was discontinued following a complete national launch. NomadGo, the 30-member startup that created it, received the notification on April 3rd.

Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluation.

Claude Mythos halved HAWK's key strength in 60 hours and enhanced attacks on the diminished AES by a factor of 200-800 times. No production systems were impacted. Each finding had a cost of approximately $100K.