{"slug": "mythos-takes-its-first-shot-at-post-quantum-cryptography", "title": "Mythos takes its first shot at post-quantum cryptography", "summary": "Anthropic's Claude Mythos Preview model improved attacks against two cryptographic algorithms, including the Hawk post-quantum digital signature candidate under NIST evaluation and a weakened version of AES-128, but neither finding compromises production systems. Anthropic said the findings improve understanding of security margins, with the Hawk attack halving its security level and requiring larger key sizes, while the AES attack improved speed by 200-800 times but remains impractical against full-strength AES.", "body_md": "Anthropic’s Claude [Mythos](https://www.csoonline.com/article/4198019/claude-mythos-faq-capabilities-access-competitors-implications.html) Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms.\n\nOne of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the other improves the best previously known attack against a weakened version of the widely used Advanced Encryption Standard ([AES](https://www.csoonline.com/article/548682/encryption-crypto-is-cracked-how-not-to-fall-in.html)).\n\nNeither finding compromises production deployments nor weakens the security of real-world systems. Instead, Anthropic said, the findings improve the understanding of the security margins of modern cryptographic designs.\n\nHawk is among the post-quantum cryptographic ([PQC](https://www.csoonline.com/article/4142174/pqc-roadmap-remains-hazy-as-vendors-race-for-early-advantage.html)) schemes under consideration by the US National Institute of Standards and Technology as it evaluates [additional algorithms](https://csrc.nist.gov/projects/pqc-dig-sig) designed to withstand attacks from quantum computers, and like some previously evaluated submissions relies on lattice-based cryptography.\n\n“Despite Hawk having survived two rounds of expert human review over a period of two years, Mythos was able to improve the best-known attack on it in just 60 hours of work,” Anthropic said in a [blog post about its research](https://www.anthropic.com/research/discovering-cryptographic-weaknesses).\n\nAnthropic only studied the 256-bit version of Hawk, while the submission NIST is evaluating concerns the 512- and 1024-bit versions. However, said Anthropic, its findings are still relevant.\n\n“The key sizes proposed in the HAWK submission are significantly weaker than originally suggested,” it said in its blog post, but for larger keys, Hawk “remains impractical to attack.”\n\nOn the other hand, the post said, [Anthropic’s attack](https://anthropic.com/document/hawk_key_recovery.pdf) makes Hawk less practical to use because it effectively halves Hawk’s security level, meaning substantially larger key sizes will be required to restore its intended security. Such an increase would diminish many of the efficiency benefits that made Hawk an attractive post-quantum signature candidate, Anthropic wrote.\n\nAnthropic’s new finding “is specific to Hawk and does not impact other NIST post-quantum signature candidates or lattice-based cryptography in general,” the company wrote.\n\nThe [second attack](https://anthropic.com/document/aes_mobius_bridge.pdf) is based on a new cryptanalytic technique, dubbed “Mobius Bridge,” which improves attacks against a weakened version of AES-128 using only seven “rounds” instead of the full-strength version’s 10. Rounds are the repeated series of mathematical transformations that AES and other encryption algorithms apply to protect data. Security researchers commonly study reduced-round variants to evaluate the security margins of block ciphers like AES.\n\nAnthropic said the new technique improving the speed of the previous best attacks by 200-800 times previous attacks on the reduced-round construction while remaining well short of threatening the full versions of AES used in production.\n\nAnthropic explicitly stated that the research has no practical impact on the security of deployed AES implementations — and for good reason.\n\n“The attack operates under a chosen plaintext threat model, which is the most common assumption used for studying ciphers like AES,” it explained in the blog post. This assumes that an attacker is able to request that the defender encrypt arbitrary inputs with a fixed, unknown key, and then gets to see the corresponding output. In this case, it assumes the attacker can request the encryption of 2^105 (about 4 billion billion billion) chosen plaintexts. “This attack is therefore completely impractical but quantifies the attack cost against AES under these assumptions,” it said.\n\nClaude Mythos Preview discovered the attack almost entirely autonomously, Anthropic said, adding, “A researcher at Anthropic built a scaffold that enabled Claude to pose hypotheses, run experiments to experimentally validate or refute these hypotheses, and then asked Claude to design an attack that improves on the best cryptanalysis of AES.”\n\nEven with AI accelerating some parts of the research, more time is spent verifying the correctness of results. The improved attack on AES was discovered in about a week, but took two researchers nearly a month to validate, Anthropic said.", "url": "https://wpnews.pro/news/mythos-takes-its-first-shot-at-post-quantum-cryptography", "canonical_source": "https://www.csoonline.com/article/4202920/mythos-takes-its-first-shot-at-post-quantum-cryptography.html", "published_at": "2026-07-29 15:17:06+00:00", "updated_at": "2026-07-29 16:05:12.971088+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-research", "ai-safety", "ai-products"], "entities": ["Anthropic", "Claude Mythos", "NIST", "Hawk", "AES", "Mobius Bridge"], "alternates": {"html": "https://wpnews.pro/news/mythos-takes-its-first-shot-at-post-quantum-cryptography", "markdown": "https://wpnews.pro/news/mythos-takes-its-first-shot-at-post-quantum-cryptography.md", "text": "https://wpnews.pro/news/mythos-takes-its-first-shot-at-post-quantum-cryptography.txt", "jsonld": "https://wpnews.pro/news/mythos-takes-its-first-shot-at-post-quantum-cryptography.jsonld"}}