AIToday

Anthropic's Mythos AI finds flaws in internet encryption standards

THE DECODER1h agoSend on LINE
Anthropic's Mythos AI finds flaws in internet encryption standards

Key takeaway

Anthropic's Claude Mythos Preview AI model discovered previously unknown mathematical weaknesses in cryptographic algorithms that protect internet security. The model found an improved attack on HAWK, a post-quantum signature candidate being reviewed by the U.S. National Institute of Standards and Technology, in 60 hours for $100,000—faster than human experts who had studied it for over two years—and a new attack on a reduced version of AES, the world's most widely used encryption standard. While Anthropic states neither finding affects current systems in use, the results show how AI models can challenge core security assumptions and uncover flaws human experts miss.

Summaries like this, in your inbox every morning.

Sign up free →

3 Key Points

  • What happened

    Anthropic's Claude Mythos Preview AI model discovered an improved attack on the post-quantum signature scheme HAWK in 60 hours for $100,000 in API costs, and found a new attack on a reduced version of the Advanced Encryption Standard (AES) in roughly 1 billion tokens for about $100,000. The HAWK attack exploits a previously undetected symmetry in the mathematical lattice underlying the scheme; the AES attack uses a new fingerprinting method called "Möbius Bridge" that improves on the best previously known attacks by a factor of 200 to 800.

  • Why it matters

    AES is the world's most widely used symmetric encryption standard for digital data, and HAWK is a candidate in the U.S. National Institute of Standards and Technology (NIST) post-quantum standardization process. Although Anthropic says neither finding affects systems in use today—HAWK is not yet standardized and the AES attack applies to a modified 7-round version rather than the full 10-round scheme—the findings demonstrate that AI models could challenge core assumptions behind internet security and uncover vulnerabilities that human experts reviewing over two years did not detect.

  • What to watch

    Anthropic shared its findings in advance with the U.S. government and industry partners and coordinated disclosure of the HAWK weakness with the scheme's authors. Mythos Preview remains unavailable to the public. Anthropic has also developed a benchmark called CryptanalysisBench with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa to let others systematically evaluate the cryptanalytic abilities of language models.

In Depth

Anthropic announced that Claude Mythos Preview, its latest AI model, has discovered previously unknown mathematical weaknesses in two cryptographic systems fundamental to internet security. The first finding concerns HAWK, a post-quantum signature scheme that is currently a candidate in the third round of the U.S. National Institute of Standards and Technology (NIST) competition for additional post-quantum signatures—schemes designed to remain secure even against future quantum computers. Human experts in theoretical computer science had reviewed HAWK for over two years, but Mythos Preview identified an improved attack in just 60 hours of computation, at an API cost of about $100,000. The attack exploits a previously undetected symmetry in the mathematical lattice on which HAWK's security relies. Importantly, Mythos worked semi-autonomously within a multi-agent system: one agent initially considered the approach infeasible, but a second agent found a way to fully exploit the discovered symmetry.

The second finding involves the Advanced Encryption Standard (AES), the world's most widely used symmetric encryption standard for digital data. Mythos Preview developed a new attack on a reduced version of AES-128 using seven of the full scheme's ten rounds. The model created what Anthropic calls a "Möbius Bridge," a new fingerprinting method that removes one of the guesses an attacker must make and improves on the best previously known attacks by a factor of 200 to 800. This work was accomplished with even less human intervention: the model generated several hundred million tokens over three days and received only three substantive prompts to keep it on track. One prompt told Mythos that researchers were "not looking for low hanging fruit," urging it to find "genuinely hard findings." Notably, the model initially refused the task, responding that "If you want a different outcome, the target has to change … AES-128 r5/r6 is just genuinely hard." The API costs for this research totaled about $100,000 for roughly 1 billion tokens, and human researchers then spent several hundred hours verifying the results.

Anthropicemphasizes that neither finding poses an immediate threat to deployed systems. HAWK has not been standardized and is still under review by NIST; the AES attack applies to a non-standard variant rather than the encryption currently protecting data worldwide. Nevertheless, the results underscore how AI models can identify subtle mathematical vulnerabilities that escape human expert review. Anthropic shared its findings in advance with the U.S. government and industry partners and coordinated the disclosure of the HAWK weakness with the scheme's authors. The company has not made Mythos Preview publicly available. In addition, Anthropic collaborated with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa to develop CryptanalysisBench, a benchmark designed to let the research community systematically evaluate the cryptanalytic abilities of language models.

Context & Analysis

Anthropic's disclosure marks a significant moment in cryptographic research: an AI model outperformed human experts in finding mathematical vulnerabilities in security-critical algorithms. The HAWK attack is particularly striking because human researchers with expertise in the field had spent over two years reviewing the scheme before Mythos Preview identified an improved attack in 60 hours. The model's discovery of a previously undetected symmetry in HAWK's underlying lattice suggests that AI systems can perceive mathematical structure in ways that differ from human intuition, even when human experts have focused scrutiny on the same problem.

The AES finding adds another dimension: Mythos initially resisted the task, writing that "AES-128 r5/r6 is just genuinely hard," but continued pursuing the problem only after being encouraged to seek "genuinely novel ideas." The resulting "Möbius Bridge" method improves efficiency by a factor of 200 to 800 over prior approaches. Both findings occurred with minimal human guidance—the HAWK work involved a project manager rather than a lattice cryptography specialist, and the AES research required only three substantive prompts over three days. This semi-autonomous capability suggests that future AI systems may discover vulnerabilities in cryptographic schemes during their development cycle, potentially allowing time for remediation before flaws become critical.

FAQ

Does this affect my encryption right now?
No. The HAWK attack applies to a scheme still in NIST's standardization process and not yet deployed. The AES attack applies to a modified version using 7 of the full scheme's 10 rounds, not the standard in use today.
How did the AI find these vulnerabilities so quickly?
For HAWK, Mythos Preview found the attack by exploiting a previously undetected symmetry in the mathematical lattice underlying the scheme, working semi-autonomously in a multi-agent system in 60 hours. For AES, the model developed a new fingerprinting method called "Möbius Bridge" that removes one guess an attacker must make and improves on the best previously known attacks by a factor of 200 to 800, generating several hundred million tokens over three days with minimal prompting.
How much did this research cost?
Each task cost about $100,000 in API fees—$100,000 for the HAWK attack over 60 hours, and approximately $100,000 for the AES attack across roughly 1 billion tokens over three days.

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Discussion

No comments yet. Be the first to share your thoughts!

Log in to join the discussion

Related Articles

Stay ahead with AI news

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.

Get Started Free

Free · takes 30 seconds · unsubscribe anytime