AI model cracks encryption schemes

Claude Mythos finds new attacks on post-quantum scheme and AES

AI, Anthropic, Mythos, AI hacking tool, Anthropic Mythos AI hacking tool access, EU gains access to Mythos AI model, ENISA evaluation of Anthropic Mythos, ENISA Mythos AI, Mythos AI, Artificial Intelligence
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: gguy / Shutterstock.com

Anthropic has developed two new cryptanalytic attacks using its AI model Claude Mythos Preview. Affected is the post-quantum scheme HAWK-256.

According to Anthropic, Claude Mythos Preview developed a previously unknown attack for full key recovery against HAWK-256, a challenge parameter of the post-quantum signature scheme HAWK. HAWK is one of nine schemes that the US standardization institute NIST advanced to the third round of its selection process for post-quantum signatures in May 2026.

Ad

The attack exploits a previously unknown symmetry in the underlying mathematical lattice and reduces the expected computational effort for key recovery from around 2 to the power of 64 to 2 to the power of 38 operations. Anthropic’s published implementation requires an average of about three hours and 42 minutes for the complete recovery on a server with 96 computing cores.

Anthropic emphasizes that the attack affects only the smaller parameter set HAWK-256, not the parameter sets HAWK-512 and HAWK-1024 that are relevant to the actual NIST standardization process. For these, Anthropic also estimates the computational effort to have decreased, but both variants remain practically unattackable.

Faster attack on reduced AES version

The second finding concerns a version of AES-128 reduced to seven of ten rounds, one of the most widely used symmetric encryption schemes. Such investigations of round-reduced variants are standard practice in cryptanalysis to assess the remaining security margin of a scheme. For this, Claude Mythos Preview developed a method Anthropic calls the Möbius Bridge, which shortens an existing meet-in-the-middle attack by removing a costly guessing step.

Ad

Depending on how it is measured, this speeds up the best known attack on the reduced AES variant by 200 to 800 times. However, the attack requires around 2 to the power of 105 chosen plaintexts under one fixed key, which places it far outside practical applicability. The full, ten-round version of AES-128 is not affected by either result.

High computational effort, even higher verification effort

For the HAWK attack, Claude Mythos Preview worked for around 60 hours in a multi-agent environment, according to Anthropic, accompanied by a researcher without a cryptography background who provided only organizational guidance. For the AES attack, the model needed around three days and several hundred million, later around one billion, output tokens in total. Anthropic also reports that the model initially refused the task, stating that an improvement over existing AES attacks was impossible, until repeated prompts from the researchers convinced it to keep going.

Anthropic put the pure API costs for both results at around 100,000 US dollars each. The subsequent verification by humans, however, was considerably more time-consuming: for the AES result, two researchers needed nearly a month, according to Anthropic, to become confident that the method was correct.

Responsible disclosure to NIST

Anthropic stated that it shared both results with HAWK’s developers as well as with US government and industry partners before publication, and coordinated the disclosure with a NIST mailing list. It is not yet publicly known whether NIST or HAWK’s developers plan to change the scheme or its status in the standardization process in response to the new estimates. At the time of publication, NIST still listed HAWK as a third-round candidate.

(red)

Ad

Weitere Artikel