Key Highlights
- Claude Mythos Preview identified an improved attack on HAWK, a post-quantum signature scheme under NIST review.
- The model also developed a faster attack on a seven-round version of AES-128 using a technique called “Möbius Bridge.”
- Anthropic said neither finding affects production systems, as HAWK is not deployed and the AES attack targets only a reduced-round version.
Anthropic AI said its Claude Mythos Preview model has identified cryptographic weaknesses in two widely studied encryption systems: HAWK, a post-quantum digital signature candidate, and a reduced version of the Advanced Encryption Standard (AES).
The findings were published on July 28 as part of the company’s Frontier Red Team research, titled “Discovering cryptographic weaknesses with Claude.” According to Anthropic, the work focused on identifying mathematical weaknesses in cryptographic algorithms rather than software implementation bugs.
Anthropic said neither finding poses an immediate risk to production systems. HAWK remains a post-quantum signature candidate under NIST review and has not been deployed, while the AES research targets only a seven-round research version of AES-128 rather than the full 10-round standard used in real-world systems.
How Claude improved attack on HAWK
HAWK is one of the remaining candidates in the U.S. National Institute of Standards and Technology’s (NIST) effort to standardize post-quantum digital signature schemes. According to Anthropic, Claude Mythos Preview identified a previously unexploited mathematical symmetry in HAWK’s lattice structure, enabling researchers to improve the best-known key-recovery attack against the scheme.
The company said the attack reduces HAWK’s effective key strength, lowering the estimated cost of attacking the smallest HAWK-256 parameter set from approximately 2⁶⁴ operations to 2³⁸ operations.
Anthropic said the finding is specific to HAWK and does not affect other NIST post-quantum cryptography candidates. It also disclosed the research to HAWK’s developers before releasing the findings.
Claude develops faster attack on reduced AES
The second finding involved a seven-round version of AES-128, a simplified version of the encryption standard commonly studied by cryptographers. Anthropic said Claude developed a new fingerprinting technique called “Möbius Bridge,” improving an existing meet-in-the-middle attack and reducing the computational work required.
According to the company, the method makes previous attacks between 200 and 800 times faster, depending on the measurement approach. Anthropic emphasized that the research does not affect the full 10-round AES-128 algorithm, which continues to protect internet communications, financial systems, and other digital services.
Researchers said Claude initially concluded that further improvements were unlikely because AES had already been extensively studied. After prompting it to continue exploring alternative approaches, the model spent several days working autonomously before developing the new technique.
Moreover, Anthropic said Claude carried out much of both projects with limited human guidance. The HAWK research took about 60 hours, while the AES work involved several days of autonomous experimentation. Each project cost roughly $100,000 in API usage, followed by weeks of human verification before publication.
Does the discovery affect Bitcoin or crypto wallets?
The research does not expose a vulnerability in Bitcoin, Ethereum, Solana, or another production blockchain. HAWK is an experimental signature candidate and is not currently used to authorise blockchain transactions.
Bitcoin, for example, relies on elliptic-curve digital signatures rather than HAWK. The newly discovered attack is specific to HAWK’s mathematical structure and does not provide a method for stealing Bitcoin private keys, forging blockchain transactions or accessing cryptocurrency wallets.
The AES research also poses no immediate threat to wallet users. Claude improved an attack against a reduced seven-round version of AES-128, while the standard form used in real-world software operates with ten rounds. The attack therefore cannot be applied directly to wallet files, exchange databases, or other systems protected by full AES encryption.
AI’s growing role in cryptography research
The latest findings build on Anthropic’s broader efforts to explore how advanced AI models can contribute to cybersecurity and cryptography research.
Earlier this month, the company introduced Claude Fable 5, its flagship AI model with updated safeguards designed to reduce misuse while improving its ability to analyze complex technical problems. Researchers at the time noted that increasingly capable AI systems could help speed up security audits and vulnerability research by analyzing large codebases and identifying subtle flaws more efficiently.
The new research involving Claude Mythos Preview extends that work beyond software analysis into cryptography itself. Instead of identifying implementation bugs, the model helped researchers develop improved attacks against cryptographic algorithms that had already undergone years of expert review.
Although the HAWK and reduced-round AES findings do not affect production systems, they suggest AI could play an important role in reviewing future cryptographic standards. Researchers also said human validation remains essential before the broader cryptography community can accept AI-generated discoveries.
Also Read: Base Unveils Onchain Identity Tool for Smart Contract Verification
