Skip to main content
CybersecurityVulnerability Management

AI Model Exposes Weaknesses in Key Encryption Algorithms

Researcher in lab setting with laptop and papers, surrounded by math references.

"The attacks described in these two papers are the strongest attacks we have found to date," Anthropic wrote in its blog post — a clear admission that an AI system has pushed cryptanalysis beyond the current state of play, even while stopping short of threatening deployed systems.

How Mythos and a human partner halved HAWK's effective strength

Anthropic researchers used Claude Mythos Preview together with a human researcher to find a substantive weakness in HAWK, a digital-signature scheme that is under review by the National Institute of Standards and Technology (NIST) as part of its search for post‑quantum cryptography (PQC). The team discovered a mathematical shortcut — a nontrivial automorphism — in the lattice structure that underpins HAWK's security.

According to Anthropic, that shortcut cuts HAWK’s effective key strength in half. Practically, the company says, key sizes would need to double to restore the same security margin, a change that would remove much of what made HAWK attractive as a candidate. Anthropic also said it followed standard disclosure practices: the company notified HAWK’s designers in June, coordinated public release with a NIST mailing list, and briefed government and industry partners ahead of publication.

The "Möbius Bridge": Mythos's shortcut against seven‑round AES

Working largely on its own, Mythos invented a technique Anthropic calls the "Möbius Bridge" against a weakened, seven‑round test version of the Advanced Encryption Standard (AES). Researchers commonly study seven‑round AES to probe security margins; real‑world AES uses 10 rounds.

Prior theoretical attacks required checking 256 separate values against a memory table. Mythos created a mathematical shortcut that eliminates that lookup step entirely. Combined with other optimizations, Anthropic reports, the discovery made the strongest known theoretical attack on seven‑round AES between 200 and 800 times faster than previously known attacks.

Anthropic emphasized the result is purely theoretical: the attack as described needs over 400 octillion messages of target data and cannot be applied to the full 10‑round AES protecting everyday software. Anthropic also noted that real‑world systems remain completely safe.

CryptanalysisBench and cross‑institution collaboration

To let other teams measure how AI systems perform against ciphers, Anthropic worked with researchers at ETH Zurich, Tel Aviv University and the University of Haifa to build a shared testing tool called CryptanalysisBench. Anthropic presented the work alongside a request for the community to develop norms around how to respond if AI systems produce cryptanalytic results that do affect deployed protections.

In its post Anthropic framed that as an open procedural question: “As we develop increasingly powerful cryptanalytic results, it would be prudent to consider how researchers should react if a language model were to discover vulnerabilities in cryptosystems where attacks do have an immediate real‑world impact,” the company wrote. It said it hopes the work will help launch those conversations.

What this means for NIST, enterprises, and cryptographers

  • NIST and PQC reviewers: Anthropic's HAWK finding is explicit evidence that candidate schemes continue to be stress‑tested during the standards process; Ellen Boehm of Keyfactor said this research “proves that the NIST PQC evaluation process is working.”
  • Enterprises and procurement leaders: Boehm warned that research like Anthropic’s “elevates the importance for organizations to have visibility of where cryptography sits inside their enterprise, what business systems and processes it’s connected to, and the need for PQC readiness.” She urged treating trust infrastructure as an ongoing operational responsibility rather than a static setting.
  • Cryptographers and researchers: The work both expands technical knowledge (new algebraic shortcuts and testing tools) and presses a policy question: how should researchers, companies and governments respond if AI finds a flaw that does affect critical infrastructure? Anthropic flagged this as unresolved and urged community discussion.

Anthropic’s results arrive amid broader debate about AI in cybersecurity. Intelligence agencies in the Five Eyes alliance warned in June that advanced AI models capable of wreaking havoc in the cyber domain are “months away,” and yet, Anthropic noted, a recent report found that despite an avalanche of bugs being unearthed, the overall threat level across the internet “has not materially changed.”

The immediate practical takeaways are narrow and concrete: HAWK would require larger keys to retain its advertised margins, seven‑round AES research is now marginally more efficient in theory, and production systems remain protected. The larger takeaway is procedural and institutional — the need for coordinated disclosure, shared testing tools like CryptanalysisBench, and a community decision on how to handle AI‑driven cryptanalysis when the consequences are not merely academic.

Read the original CyberScoop story: https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/