Anthropic's Claude Mythos Advances Cryptographic Research with New Attacks

Jul 29, 2026 763 views

Anthropic’s Claude Mythos Preview model is making waves in the cryptographic community by revealing new vulnerabilities in notable algorithms. Notably, it has improved existing attacks on Hawk, a candidate for post-quantum digital signatures undergoing evaluation by NIST, and enhanced efforts against a weakened variant of the Advanced Encryption Standard (AES).

Importantly, these findings do not compromise existing deployments or weaken the security of operational systems. Instead, they offer valuable insights into the security margins of contemporary cryptographic frameworks. Anthropic asserts that such revelations bolster the understanding of modern cryptography rather than undermine its integrity.

Security Margin Assessment

Hawk, among the post-quantum cryptographic (PQC) schemes under NIST evaluation, employs lattice-based cryptography, a growing area of interest in the context of quantum-resilient algorithms. Even after two years of extensive scrutiny and evaluations, Claude Mythos managed to refine the best-known attack on Hawk within a mere 60 hours, showcasing a notable efficiency.

This is more significant than it looks. Hawk's position as a contender for post-quantum standards means its vulnerabilities could have broader implications for the future of digital security as the quantum era threatens to render existing systems obsolete. While Anthropic's focus was primarily on the 256-bit variant of Hawk, and NIST considers versions that are 512 and 1024 bits, these initial findings still hold relevance. The company noted that key sizes previously proposed in Hawk are weaker than expected, yet with larger keys, the algorithm remains difficult to breach.

However, this research implies a potential drawback for practical deployment. Anthropic indicates that its findings effectively halve Hawk’s security level, necessitating larger key sizes to meet the original security expectations. This increase may negate many of the efficiency advantages that made Hawk an appealing post-quantum candidate. It raises an important question: can Hawk remain attractive to developers and businesses if its key sizes must double just to maintain its security benchmarks?

It’s essential to clarify that Anthropic's discoveries are exclusive to Hawk and do not extend their impact to other NIST post-quantum options or to lattice-based techniques in general. Still, for the crypto community, this distinction may be moot. If one promising post-quantum algorithm shows signs of vulnerability, it could trigger skepticism about others in the pipeline.

Advancements in AES Security Testing

The second centerpiece of Anthropic's findings involves a new cryptanalytic technique—termed “Mobius Bridge”—which significantly enhances attacks against a reduced-round variant of AES-128. This method operates effectively on just seven rounds, compared to the traditional ten-round structure, allowing researchers to scrutinize the security margins of AES more incisively.

According to Anthropic, the new technique has expedited attacks by an astonishing 200 to 800 times, without threatening the integrity of full AES implementations utilized in real-world applications. This doesn't mean those implementations are suddenly at risk; rather, it opens a window into understanding how secure these systems are under specific, controlled conditions.

Research with Limited Practical Implementation

Anthropic has made it clear that the implications of this research do not affect live AES deployments. The attack operates under a chosen plaintext assumption—an approach where an attacker can request encryption of arbitrary inputs to see the encrypted outputs, while remaining impossible to execute in a practical scenario due to exceedingly high computational demands of around 2^105 chosen plaintexts. It's clear that powerful resources and computational time are substantial barriers, making practical exploitation unlikely in real-world scenarios.

The discovery process for these attacks involved a high degree of autonomy from Claude Mythos, which was guided by Anthropic researchers. They designed a scaffold enabling Claude to generate hypotheses, conduct experimental validations, and ultimately propose an enhanced attack on AES's best-known cryptanalysis techniques. Despite the efficiency gains from AI involvement, substantial time was dedicated to verifying results—nearly a month was spent validating the improved AES attack, a testament to the complexity of the research process. This highlights a broader truth: as we integrate AI more deeply into cryptographic research, the relationship between human insight and machine capability will be vital.

Implications and Future Outlook

This intersection of AI and cryptography raises important questions about the future of secure systems. If you're working in this space, these findings should prompt you to rethink assumptions about security protocols. While the research from Claude Mythos is centered on specific vulnerabilities, it may catalyze a wider reevaluation across various cryptographic algorithms. The digital security community can't afford to overlook this revelation.

As businesses transition to post-quantum solutions, ongoing scrutiny much like what Anthropic has demonstrated will become essential. It may also prompt other researchers to develop alternative techniques to protect against adaptive attacks that mix AI and cryptography. If history teaches us anything, it's that as one door closes on security, another often opens with unforeseen vulnerabilities. And this is the part most people overlook—improved cryptography might invite new attack vectors even as it shores up defenses.

As we anticipate the full deployment of post-quantum cryptography, findings like these from Claude Mythos may help sharpen our understanding and guide future innovations. The balance between adopting newer methods and ensuring their effectiveness without creating new vulnerabilities will be vital. This ongoing dialogue will shape the next phase of digital security, and observers should pay close attention.

Source: Michael Brown · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Mythos takes its first shot at post-quantum cryptography