Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

by | Aug 2, 2026 | Technology

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

A post-quantum cryptographic algorithm called HAWK has been taken out of consideration for official US standards following the discovery of a significant vulnerability through Anthropic’s Mythos AI security model. The algorithm, designed as a digital signature scheme to withstand potential future attacks from quantum computers, had successfully completed two rounds of testing by the National Institute of Standards and Technology before encountering the fatal weakness during its third-round evaluation. Following Anthropic’s announcement of the findings, HAWK’s developer withdrew the algorithm from consideration.

Anthropic’s Mythos model, deployed in a semi-autonomous configuration with human guidance, identified a previously unknown mathematical method for attacking HAWK’s underlying security foundation, known as the Lattice Isomorphism Problem. Through approximately 60 hours of computational work costing around $100,000, the AI system developed an improved attack that effectively reduced the algorithm’s key strength by half. While the weakness could theoretically be mitigated by doubling the key size, the resulting computational burden makes HAWK less desirable compared to alternative post-quantum digital signature schemes currently available.

Cryptography experts have noted that the discovery, while significant, relied on combining existing mathematical techniques rather than inventing entirely new ones. A Google researcher specializing in post-quantum cryptography stated that HAWK was already suspected of harboring such vulnerabilities. The attack methodology reduced the competitiveness of HAWK relative to other post-quantum algorithms such as ML-DSA and FN-DSA, making it a less viable option for standardization.

Anthropica also reported using Mythos to discover an improved attack against AES, the widely used encryption standard, though with less dramatic results. The improved technique reduced the number of inputs required for a theoretical attack, though the advancement remains impractical outside controlled laboratory conditions. Researchers emphasized that the tested versions were intentionally weakened variants used in adversarial peer review, while production-grade cryptosystems remain considerably more robust.

The findings raise questions about the potential role of AI in cryptanalysis while highlighting important caveats about the scope and practical applicability of the discoveries. The results demonstrate incremental advances in attacking cryptographic systems rather than fundamental breaches of systems currently in use for protecting sensitive information.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI