Scott Aaronson Says AI Labs Are Quietly Testing Models Against Encryption Scott Aaronson, a theoretical computer scientist at UT Austin, wrote in an October 7 blog post titled "The Mathocalypse" that several AI companies have begun using their newest internal models to attack "important cryptographic protocols and primitives" and are keeping the results private, a claim he attributes to sources he trusts rather than a named lab. Aaronson's post noted that cryptography is absent from OpenAI's October 6 GitHub release of 719 AI-generated mathematical manuscripts across 372 result families, produced by an unreleased internal model with Lean formal verification for many claims. The concern follows Anthropic's July 2026 disclosure that its Claude Mythos Preview model, run by the Frontier Red Team, found a previously unexploited symmetry in the lattice-based signature scheme HAWK in about 60 hours and built a key-recovery attack that Anthropic says halves the scheme's effective key strength. Scott Aaronson says AI companies have started pointing their newest internal models at the cryptography that secures the internet, and he noticed the silence around it before anyone said a word. Something was missing from OpenAI's biggest math dump of the year, and Aaronson was the one who caught it. On October 6, OpenAI published a large GitHub catalogue of AI-generated mathematical manuscripts. As of October 8, the repository lists 719 manuscripts organized into 372 distinct result families, produced by an unreleased internal model and accompanied by Lean formal verification for many of the claims. Mathematicians spent the next day combing through them. Aaronson, a theoretical computer scientist at UT Austin who writes the blog Shtetl-Optimized, spent it noticing what wasn't there. In an October 7 post he titled "The Mathocalypse," Aaronson pointed out that cryptography is conspicuously absent from that list of hundreds of results. Not a minor omission, in his reading. The model chewed through a decade of unsolved problems in sphere packing, coding theory and group theory. You'd think it would also take a swing at the number theory underneath RSA, or the algebraic structure behind elliptic curve cryptography. It didn't, at least not in public. Aaronson wrote that he has it from sources he trusts that several AI companies have already started using their newest internal models to take a run at breaking "important cryptographic protocols and primitives." They are keeping the results to themselves. Andrew Curran, a widely followed AI commentator, relayed the claim on X the same day, and it was picked up quickly by Techmeme and a wave of tech outlets. That's a secondhand claim, sourced to people Aaronson trusts rather than a named lab with a named protocol. He didn't say whether anyone has actually broken anything. What makes it land is the comparison he draws: physicists working on nuclear fission in the 1930s kept publishing freely, until suddenly they didn't, and the silence itself became the tell that something serious was happening behind closed doors. Aaronson is suggesting the same pattern might now apply to cryptanalysis. Here's the thing: you don't actually need to take Aaronson's word for it to find this unsettling, because a version of it already happened in public. In July 2026, Anthropic's Frontier Red Team put its research model, Claude Mythos Preview, to work against two real cryptographic targets. The first was HAWK, a lattice-based digital signature scheme under evaluation by the U.S. National Institute of Standards and Technology as a post-quantum standard. In about 60 hours, Claude Mythos found a previously unexploited mathematical symmetry in HAWK's lattice structure and used it to build a key-recovery attack that, according to Anthropic, cuts the scheme's effective key strength in half. HAWK had already survived two years of expert cryptanalytic review. The fix is straightforward, doubling the key sizes, but someone had to find the flaw first, and this time it wasn't a person. OpenAI and Anthropic Are Quietly Probing Tens of Thousands of AI Security Incidents https://startupfortune.com/openai-and-anthropic-are-quietly-probing-tens-of-thousands-of-ai-security-incidents/ Axios reports that OpenAI and Anthropic are investigating tens of thousands of security incidents involving their AI models and agents, most never disclosed publicly. The finding follows a month of individual failures, from a DNS-based sandbox escape at OpenAI to a nine-zero-day breach of Hugging Face, and raises hard questions about whether any... - how AI models escape sandbox security measures https://startupfortune.com/openai-and-anthropic-are-quietly-probing-tens-of-thousands-of-ai-security-incidents/ - anthropic and openai security incident investigation details https://startupfortune.com/openai-and-anthropic-are-quietly-probing-tens-of-thousands-of-ai-security-incidents/ The second result involved a scaled-down, seven-round research version of AES, the symmetric cipher that underlies most of the world's encrypted traffic in its full 10-to-14-round form. Claude Mythos developed an attack 200 to 800 times faster than the best previously known technique against that reduced version. Anthropic framed both results as research advances rather than live threats. HAWK was never deployed, and the AES variant was deliberately weakened for study, not the cipher anyone actually uses to encrypt a bank transfer or a crypto wallet. Anthropic also disclosed the cost of getting there, roughly $100,000 in model usage for each of the two attacks, with human researchers then spending considerable time independently validating what the model had found. Put those two stories side by side and the picture gets sharper. One frontier lab has already shown, publicly and with its name on it, that a large model can out-cryptanalyze two years of expert human review on a candidate standard. Another researcher is now saying, based on sources rather than a press release, that labs are pointing similar capability at live, deployed protocols and not talking about what they find. Neither claim requires the other to be true. Together they make Aaronson's silence argument harder to wave off as paranoia. None of this is the same conversation as quantum computing, and it's worth being precise about that distinction. Aaronson has separately and loudly warned about a fault-tolerant quantum computer, one capable of breaking RSA and elliptic curve cryptography outright via Peter Shor's 1994 algorithm. That could plausibly arrive around 2029, based on what he's hearing from people he trusts in quantum hardware and error correction. That's a hardware problem with a rough timeline. What he flagged this week is different: a software and compute problem with no timeline at all. A large language model, running on ordinary GPUs, finding mathematical shortcuts that make existing cryptosystems weaker without needing a quantum computer in the room. For crypto exchanges and blockchain networks that lean on elliptic curve signatures for wallet security, the Anthropic result is the one to actually read, not Aaronson's sourced claim. It shows the shortcut-finding already works on a real, standards-track scheme, just not yet on the specific curves securing a Bitcoin or Ethereum wallet today. The honest summary is: nothing in production has broken. But the labs doing the stress-testing are the ones best positioned to know first if that changes, and right now the people building on top of these protocols are relying on those same labs to say so. Also read: Samsung's LittleBit squeezes AI models to a tenth of a bit per weight https://startupfortune.com/samsungs-littlebit-squeezes-ai-models-to-a-tenth-of-a-bit-per-weight/ • Researchers find letting AI coding agents write their own tests backfires https://startupfortune.com/researchers-find-letting-ai-coding-agents-write-their-own-tests-backfires/ • Independent mathematicians are now Lean-checking OpenAI's proof claims line by line https://startupfortune.com/independent-mathematicians-are-now-lean-checking-openais-proof-claims-line-by-line/ This article is posted in AI News https://startupfortune.com/category/ai/ , check it out for more related stories. OpenAI, Anthropic and Over 100 Firms Warn AI Cyberattacks Are Months Away https://startupfortune.com/openai-anthropic-and-over-100-firms-warn-ai-cyberattacks-are-months-away/ OpenAI, Anthropic, Microsoft and more than 100 other companies, including CrowdStrike, Visa and Capital One, signed an August 27, 2026 letter warning that AI-powered cyberattacks on hospitals and water systems are months, not years, away. The same labs sounding the alarm are already selling the defensive AI tools meant to stop it. - AI powered cyberattacks on critical infrastructure timeline https://startupfortune.com/openai-anthropic-and-over-100-firms-warn-ai-cyberattacks-are-months-away/ - when will AI cyberattacks happen to hospitals https://startupfortune.com/openai-anthropic-and-over-100-firms-warn-ai-cyberattacks-are-months-away/ Join the discussion Open in the community → https://startupfortune.com/community/ Almost there. Sign in and your reply posts straight away.