
Anthropic announced that its Mythos AI security model identified a significant vulnerability in HAWK, a post-quantum cryptographic digital signature algorithm designed to resist attacks from future quantum computers. Following the discovery, the algorithm’s developer withdrew HAWK from the third round of testing being conducted by the National Institute of Standards and Technology (NIST) to evaluate post-quantum cryptographic candidates.
The Mythos model discovered a previously unknown method for finding automorphism symmetries in the mathematical problem underlying HAWK’s security, effectively reducing the algorithm’s key strength by half. An Anthropic researcher with no prior cryptography expertise used approximately 60 hours of computational work costing around $100,000 to identify the improved attack. While this weakness could be mitigated by doubling the key size, the resulting additional computational burden makes HAWK less competitive than other available post-quantum digital signature schemes such as ML-DSA and FN-DSA.
Anthropic also reported that Mythos discovered improvements to attacks against the widely used AES cipher, reducing the number of plaintext inputs required for a meet-in-the-middle attack from approximately 2105 to 289. However, multiple caveats apply to both findings. The tested cryptosystems were deliberately weakened versions provided for adversarial peer review rather than production-strength implementations. The underlying mathematical problems remain secure, and the attack methods would likely be infeasible outside of controlled testing environments.
Cryptography experts noted mixed significance in the findings. Matthew Green, a Johns Hopkins cryptography professor, highlighted that the HAWK attack’s strength lay in novel combinations of existing techniques rather than fundamentally new mathematical discoveries. Google’s Sophie Schmieg confirmed that HAWK was already suspected to have eventual vulnerabilities, making Mythos’s contribution meaningful but not entirely unexpected in the research community.
The results underscore both the potential and limitations of AI-assisted cryptanalysis, with Anthropic cautioning that the implications for future cryptographic research remain uncertain. Industry observers noted that while the findings warrant serious attention for their methodological contributions, determining whether AI truly provides significant advantages over conventional cryptanalysis requires further evidence and broader testing across established cryptographic systems.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI