Jul 28, 2026
AI

Anthropic Mythos cryptography tests find weaknesses in HAWK and reduced AES

Anthropic says Claude Mythos Preview found attacks on HAWK and a reduced AES variant, with no immediate impact on deployed systems.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

Anthropic Mythos cryptography tests find weaknesses in HAWK and reduced AES
Photo: The Decoder

Anthropic Mythos cryptography research found mathematical weaknesses in two algorithms tied to digital security, the company said: an improved attack on the post-quantum signature candidate HAWK and a new attack on a reduced version of AES. Anthropic said neither result affects systems currently in use, but the work is a notable marker for frontier AI models in technical security research because each run cost about $100,000 in API usage and required limited substantive prompting.

The company said Claude Mythos Preview, a model Anthropic has not made publicly available, worked largely through a multi-agent setup. Human researchers mostly handled project management, supplied simple prompts, and later checked the model's results, according to Anthropic.

What did Anthropic Mythos find in cryptography?

Anthropic said Mythos found an improved attack on HAWK, one of the remaining schemes in the third round of the U.S. National Institute of Standards and Technology process for additional post-quantum signatures. Post-quantum signatures are intended to remain secure against future quantum computers. HAWK is still a candidate in that process, rather than a deployed internet standard.

According to Anthropic, human specialists had reviewed HAWK for more than two years before Mythos identified a weakness in about 60 hours. The company said the attack uses a previously unnoticed symmetry in the mathematical lattice on which HAWK's security depends.

Anthropic described the HAWK work as semi-autonomous. In its account, one agent initially treated the idea as impractical, while another agent found a way to exploit it. The human researcher involved had a theoretical computer science background but was not a lattice-cryptography specialist, and Anthropic said his role was mainly project management. API costs for the run were roughly $100,000.

Does the AES finding affect encryption used today?

Anthropic said the AES result does not affect full AES as used today. The attack applies to a modified AES-128 version using 7 rounds, compared with 10 rounds in the full scheme. AES is the most widely used symmetric encryption standard for digital data, so even reduced-round work will draw attention from cryptographers, but Anthropic did not claim a practical break of deployed AES.

For the AES work, a researcher created a scaffold that let Claude generate hypotheses and test them experimentally. Anthropic said Mythos then developed a fingerprinting method it calls Möbius Bridge. The company said the method removes one guess an attacker would otherwise need to make and improves on the best previously known attacks by a factor of 200 to 800.

Anthropic also said the model initially resisted the AES task, treating further progress as unlikely, before a researcher encouraged it to look for novel ideas. Over three days, Mythos generated several hundred million tokens and received only three additional substantive prompts, according to the company. That run cost about $100,000 in API fees for roughly 1 billion tokens. Human researchers who were not cryptography experts then spent several hundred hours verifying the results, Anthropic said.

How is Anthropic handling disclosure?

Anthropic said it shared the findings ahead of publication with the U.S. government and industry partners. The company also said it coordinated disclosure of the HAWK weakness with the scheme's authors.

Anthropic has kept Mythos Preview closed. The company also worked with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa on CryptanalysisBench, a benchmark intended to evaluate language models' cryptanalytic abilities. The benchmark gives outside researchers a way to test claims in this area, although Anthropic's most capable reported system for this work remains unavailable for public evaluation.

This story draws on original reporting from The Decoder.

More from AI

All AI →