Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

by | Aug 12, 2026 | Technology

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

A post-quantum cryptographic algorithm called HAWK has been withdrawn from consideration as an official US standard following the discovery of a critical vulnerability. Anthropic’s Mythos AI security model identified a mathematical weakness in HAWK’s underlying security structure, the Lattice Isomorphism Problem, which effectively halved the algorithm’s key strength. The researcher who conducted the analysis required approximately 60 hours of computational work costing around $100,000 to identify this previously unknown attack method, despite having no background in cryptography.

HAWK was a digital signature scheme designed to resist attacks from quantum computers and had successfully passed two rounds of evaluation by the National Institute of Standards and Technology (NIST) before being selected for a third round of testing. The flaw discovered through Mythos analysis rendered HAWK uncompetitive compared to other post-quantum cryptographic signing algorithms such as ML-DSA and FN-DSA. The developer of HAWK announced the algorithm’s withdrawal Tuesday, following Anthropic’s Monday announcement of the discovery.

Anthropologic researchers deployed multiple AI agents working largely independently to identify the attack, combining several existing mathematical methods in a novel configuration that no previous researchers had attempted. The discovery process involved extensive literature review, mathematical reasoning, and computational experiments, ultimately producing an end-to-end verification pipeline. Google’s post-quantum cryptography expert noted that while HAWK weaknesses were suspected, the specific attack method made the candidate significantly less attractive than established alternatives.

Anthropic also reported using Mythos to improve attacks against AES, a widely used encryption cipher, reducing the computational requirements for a meet-in-the-middle attack from 2105 to 289 plaintext inputs. However, the company emphasized that these findings remain incremental, representing improvements against weakened test versions rather than production cryptosystems, and the attacks would remain infeasible outside controlled laboratory environments. The research demonstrates growing evidence that large language models may provide advantages in cryptanalysis while raising questions about whether such AI discoveries signal fundamental shifts in cryptographic security research.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI