Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

by | Aug 22, 2026 | Technology

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

A post-quantum cryptographic algorithm called HAWK has been withdrawn from consideration as a potential US standard following the discovery of a significant weakness. The flaw was identified using Mythos, an AI security model developed by Anthropic that was given access to cryptographic challenge problems for adversarial testing.

HAWK is a digital signature scheme designed to resist attacks from quantum computers and had progressed through two rounds of evaluation by the National Institute of Standards and Technology before being subjected to third-round testing. An Anthropic researcher with no cryptography expertise used Mythos to discover a previously unknown method for identifying mathematical symmetries that effectively halved the effective key strength of the algorithm. The work required approximately 60 hours and $100,000 in computational resources. While the weakness could theoretically be mitigated by doubling the key size, this approach significantly increases computational overhead, making HAWK less competitive than other available post-quantum cryptographic options.

The Mythos model operated semi-autonomously with occasional human guidance to develop and verify the attack. The breakthrough demonstrated the effectiveness of combining existing mathematical techniques in novel ways rather than developing fundamentally new mathematics. According to experts, the discovered weakness makes HAWK unviable as a standardized algorithm compared to alternatives such as ML-DSA and FN-DSA.

Anthropric also reported that Mythos identified improvements to attacks against AES, a widely used cipher, though with less dramatic consequences. The improvements to meet-in-the-middle attacks on a weakened version of AES potentially reduced computational requirements by orders of magnitude, though researchers emphasized the attacks remain impractical outside controlled laboratory environments.

Experts noted that the tested cryptosystems used weakened versions from formal specifications rather than production implementations, and the findings represent incremental improvements rather than complete breaks of systems currently in use. Despite these caveats, the results suggest potential advances in cryptanalytic capabilities relevant to long-term security considerations.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI