Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

by | Jul 30, 2026 | Technology

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

A post-quantum cryptographic algorithm called HAWK has been removed from the running to become an official US standard following the discovery of a critical vulnerability. Anthropic’s Mythos AI security model identified a mathematical weakness in HAWK’s underlying Lattice Isomorphism Problem that effectively reduced its key strength by half. The algorithm’s developer announced the withdrawal on Tuesday, after Anthropic disclosed its findings on Monday.

HAWK had previously withstood two rounds of testing by NIST’s post-quantum cryptography evaluation process and was undergoing a third round specifically designed to identify such flaws. The vulnerability was discovered through approximately 60 hours of computational work costing around $100,000. An Anthropic researcher without cryptography expertise used Mythos to develop a previously unknown method for finding automorphism symmetries, a mathematical technique that breaks the algorithm. While the weakness could be addressed by doubling the key size, the resulting computational overhead makes HAWK less practical than alternative post-quantum digital signature schemes like ML-DSA and FN-DSA.

Experts noted that the discovery combines existing mathematical tools in novel ways rather than inventing fundamentally new mathematics. The Mythos model worked semi-autonomously with human guidance, conducting literature reviews and mathematical reasoning to identify the attack. Two separate agents initially disagreed on the method’s viability before eventually working together to confirm its effectiveness.

AnthropicAlso reported improvements to theoretical attacks against AES, a widely-used cipher, though those results were less dramatic. The findings demonstrate AI’s potential role in cryptanalysis while researchers emphasize important caveats: the tested algorithms were weakened versions, the attacks remain impractical outside laboratory settings, and production implementations are more robust. The results signal potential advances in breaking cryptography crucial to privacy and security, though their practical impact on currently deployed systems remains limited.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI