Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

by | Aug 26, 2026 | Technology

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

A post-quantum cryptographic algorithm named HAWK has been withdrawn from consideration as an official US standard following the discovery of a critical vulnerability. Anthropic’s Mythos AI security model identified a weakness in HAWK’s mathematical foundations that had not been detected during two previous rounds of testing by NIST. The developer announced the withdrawal on Tuesday, one day after Anthropic publicly disclosed its findings.

The flaw targets the Lattice Isomorphism Problem, the mathematical basis underlying HAWK’s security design. An Anthropic researcher without cryptography expertise used Mythos to develop a previously unknown method for finding automorphism symmetries in approximately 60 hours at a computational cost of about $100,000. This novel approach effectively reduced HAWK’s key strength in half, a significant degradation that undermines the algorithm’s practical utility compared to alternative post-quantum signature schemes already available.

Cryptography experts noted that while the discovery is noteworthy, the attack represents a combination of existing mathematical techniques rather than fundamentally new mathematics. According to a Johns Hopkins cryptography professor, the significance lies in Mythos identifying tools that had been known but never previously combined in this manner. The vulnerability can technically be mitigated by doubling the key size, but the resulting computational overhead makes HAWK less competitive than existing post-quantum digital signature algorithms.

Anthropicalso demonstrated Mythos’s capabilities against AES, a widely used encryption cipher, by improving existing attacks. The model developed an enhanced meet-in-the-middle technique that reduced the number of plaintext inputs required for an attack from approximately 2105 to 289, potentially accelerating such attacks by 200- to 800-fold. However, experts emphasized that these findings remain largely experimental and do not compromise cryptosystems currently in operational use. The attacks employed weakened versions of the algorithms designed specifically for adversarial testing, and the practical feasibility of these methods remains limited to laboratory environments.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI