Claude discovered mathematical errors in two cryptographic algorithms that went unnoticed by years of expert evaluation.
**TL;DR** Claude Mythos identified mathematical vulnerabilities in HAWK (halving its key strength) and enhanced the attack on reduced-round AES (200-800x quicker). Both findings were largely autonomous, with no impact on production systems. Each discovery incurred a cost of about $100K.
On Monday, Anthropic revealed that Claude Mythos Preview has uncovered mathematical flaws in two cryptographic algorithms. The first significantly compromises HAWK, a post-quantum digital signature scheme currently under NIST review, by halving its effective key strength. The second discovery amplifies the most effective attack on seven-round AES, the leading symmetric cipher, by 200 to 800 times. Neither finding affects operational systems; HAWK is yet to be implemented, and the AES attack focuses on a reduced version, not the complete cipher.
This differs critically from Anthropic’s prior cybersecurity endeavors. Previously, Claude had identified weaknesses in cryptographic libraries—issues stemming from how programmers executed algorithms. These recent findings highlight defects in the algorithms' mathematics themselves, unearthed after years of expert human review failed to reveal them. HAWK underwent two NIST evaluation phases over two years. Mythos identified the flaw in just 60 hours of semi-autonomous effort, with minimal guidance from a researcher for project management rather than technical support. The AES finding was almost entirely autonomous, with Claude initially refusing to pursue it, asserting that improvement was not feasible. After three encouraging prompts over three days from a researcher, Claude produced one billion output tokens and developed a method it termed the “Möbius Bridge.”
Each discovery cost around $100,000 in API compute. Anthropic adhered to responsible disclosure protocols, informing HAWK's authors and coordinating with NIST, the US government, and industry partners prior to making the findings public. The company also collaborated with ETH Zurich, Tel Aviv University, and the University of Haifa to launch CryptanalysisBench, a benchmark for assessing AI cryptanalytic capabilities. Over the span of one month, Claude Mythos identified 10,000 critical software vulnerabilities, transitioning from implementation errors to mathematical flaws signifies a significant advancement in AI's role in securing infrastructure.
Anthropic acknowledged subsequent results: a practical attack on 13-round LEA that retrieves keys in less than an hour on a desktop, and attacks on Serpent-128, Salsa20, Poseidon, and SHA-1. “In just one year, language models have evolved from being unable to perform cryptanalysis of even basic ciphers to being capable of discovering flaws in cryptographic designs that had eluded detection despite years of human expert analysis,” the company stated. The White House initiated Gold Eagle to oversee AI-driven cyber defense, but there’s no similar program for cryptographic assessment. The critical question posed by Anthropic at the end of its announcement is what occurs when a model identifies a weakness in a cipher already securing production systems.
Other articles
Claude discovered mathematical errors in two cryptographic algorithms that went unnoticed by years of expert evaluation.
Claude Mythos halved HAWK's key strength within 60 hours and enhanced attacks on the diminished AES by 200-800 times. Production systems remain unaffected. Each discovery incurred a cost of approximately $100K.
