Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluations.
**Summary:** Claude Mythos has identified mathematical vulnerabilities in HAWK (halving its key strength) and a significantly faster attack on reduced-round AES (200-800 times quicker). These findings were largely autonomous, with no impact on current production systems, and each discovery cost around $100,000.
On Monday, Anthropic revealed that Claude Mythos Preview has uncovered mathematical flaws in two cryptographic algorithms. The first one considerably diminishes HAWK, a post-quantum digital signature scheme currently under NIST evaluation, by halving its effective key strength. The second finding enhances the attack on seven-round AES, the most common symmetric cipher, making it 200-800 times more effective. Neither finding influences production systems; HAWK is not in use, and the AES attack pertains to a reduced variant rather than the complete cipher.
This distinction contrasts with Anthropic’s previous cybersecurity efforts. Earlier, Claude identified weaknesses in cryptographic libraries caused by programmer errors in algorithm implementation. In contrast, these recent findings reveal flaws within the algorithms' mathematics, which had eluded detection despite years of scrutiny by experts. HAWK survived two reviews by NIST over two years, while Mythos identified its weakness in 60 hours of semi-autonomous work, with minimal project management oversight from a researcher. The AES discovery was largely autonomous; after initial reluctance to engage, Claude was prompted positively over three days, eventually generating one billion output tokens and developing a technique called the “Möbius Bridge.”
The expenses for each discovery totaled about $100,000 in API compute costs. Anthropic adhered to responsible disclosure protocols, informing HAWK's authors and collaborating with NIST, the US government, and industry partners prior to publicizing the findings. Additionally, the company worked with ETH Zurich, Tel Aviv University, and the University of Haifa to introduce CryptanalysisBench, a benchmarking tool for evaluating AI capabilities in cryptanalysis. In one month, Claude Mythos discovered 10,000 critical software vulnerabilities, marking a significant progression from implementation errors to algorithmic flaws, showcasing the enhanced potential of AI in securing infrastructures.
Anthropic also noted follow-up findings: a practical attack on 13-round LEA that can recover keys in under an hour on a desktop, as well as attacks on Serpent-128, Salsa20, Poseidon, and SHA-1. The company emphasized that in just one year, language models have evolved from being incapable of cryptanalysing even basic ciphers to identifying flaws in cryptographic designs that have been overlooked despite extensive human examination. The White House has launched Gold Eagle to facilitate AI-driven cyber defense, though there is no comparable initiative for cryptographic review. The critical question posed by Anthropic is what the implications will be when a model uncovers a flaw in a cipher currently securing production systems.
Other articles
Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluations.
Claude Mythos halved HAWK's key strength in 60 hours and enhanced attacks on the lowered AES by 200-800 times. There is no impact on production systems. Each discovery incurred a cost of approximately $100K.
