Back to AI
Anthropic's AI Model Cracks a Post-Quantum Algorithm That Survived Years of NIST Review
AI

Anthropic's AI Model Cracks a Post-Quantum Algorithm That Survived Years of NIST Review

Jul 301 views

Key takeaways

  • Anthropic's Mythos AI model helped identify a flaw in HAWK that halved its key strength, prompting the algorithm's developer to withdraw it from NIST's post-quantum cryptography evaluation.
  • The discovery took roughly 60 hours and $100,000 in compute costs, and was guided by a researcher with no prior cryptography expertise — highlighting AI's ability to synthesize complex technical literature rapidly.
  • Both the HAWK and AES findings involved weakened test versions rather than production cryptosystems, and neither represents an immediately exploitable threat to real-world security.

A post-quantum cryptographic algorithm that had spent years under rigorous evaluation has been withdrawn from contention as a potential US standard after Anthropic's AI security model, Mythos, helped identify a previously unknown vulnerability. The algorithm in question, HAWK, is a digital signature scheme built to resist attacks from future quantum computers. It had successfully navigated two full rounds of testing by the National Institute of Standards and Technology before Mythos found the flaw during a third evaluation round — the very stage designed to surface exactly this kind of critical weakness.

The discovery came from an Anthropic researcher with no specialized cryptography background who, working semi-autonomously alongside Mythos, prompted the model through an extensive literature review, mathematical reasoning sessions, and computational experiments. The process cost roughly $100,000 in compute time and around 60 hours of work. Mythos deployed two independent agents during the process: one initially dismissed a candidate attack method as unworkable, while the second found a viable path forward. The agents eventually converged and jointly confirmed the attack was effective, after which Mythos built a verification pipeline to validate the result.

The core of HAWK's security rests on the Lattice Isomorphism Problem, a mathematical challenge considered resistant to quantum computing attacks. The best-known classical attack exploits automorphism symmetries, and Mythos produced a previously undiscovered method for identifying those symmetries that effectively cut HAWK's key strength in half. While doubling the key size could patch the vulnerability in theory, doing so adds enough computational overhead to make HAWK less attractive than competing post-quantum signing algorithms like ML-DSA and FN-DSA. Following Anthropic's Monday announcement, HAWK's developer formally withdrew the algorithm on Tuesday.

Sopie Schmieg, a Google engineer specializing in post-quantum cryptography, noted that weaknesses in HAWK had long been suspected but not yet demonstrated with this level of impact. Johns Hopkins cryptography professor Matthew Green highlighted a particularly telling characteristic of the finding: the attack did not rely on any new mathematics, but instead stitched together several existing, well-known tools that no one had previously thought to combine. That kind of synthesis, Green suggested, is precisely where AI systems excel and human researchers can fall short.

Anthropic also reported a secondary finding against a weakened version of AES, where Mythos improved the best-known meet-in-the-middle attack by incorporating a Möbius Bridge fingerprinting technique, reducing required plaintext inputs from roughly 2^105 to 2^89. The company was careful to frame both results with important caveats: neither breaks any cryptosystem in active use today, both were tested against deliberately weakened challenge instances rather than production implementations, and the AES improvement remains computationally infeasible outside laboratory conditions. Despite those limitations, Anthropic argued that the findings mark a meaningful shift in the pace and nature of AI-assisted cryptanalysis.

The bigger picture

What makes this episode genuinely significant is not that HAWK was broken in any practical, immediate sense — it wasn't. What matters is the demonstration that an AI model, guided by a non-expert human, could synthesize years of accumulated cryptographic literature into a novel attack vector in roughly 60 hours. That kind of accelerated, semi-autonomous research capability changes the threat landscape for cryptographic standards in ways the security community is only beginning to absorb. NIST's multi-year evaluation process has always depended on the assumption that adversarial peer review scales with the complexity of the algorithms being tested. Mythos suggests that assumption may no longer hold.

For the broader competitive landscape in AI security tools, this is also a striking signal. Anthropic is positioning Mythos not just as a research curiosity but as a genuine cryptanalysis accelerant — one it is currently restricting to a trusted circle of users, which itself raises questions about asymmetric access to powerful offensive research tools. The fact that Anthropic is openly reporting these findings is responsible, but the underlying capability will not remain proprietary indefinitely. Other labs with comparable model capabilities will likely attempt similar research, and the question of what stays unpublished — and by whom — becomes increasingly fraught.

The HAWK withdrawal also illustrates a subtler dynamic in post-quantum cryptography standardization: algorithms that survive years of human-led review are not necessarily safe, they may simply have reached the limits of what human pattern-matching can efficiently surface. As AI-assisted cryptanalysis matures, NIST and the broader standards community may need to rethink evaluation timelines, the scope of challenge instances, and how quickly discoveries like this one should be disclosed publicly versus quietly remediated. Readers should watch whether NIST revises its third-round evaluation methodology in response, and whether any other PQC candidates now face renewed AI-assisted scrutiny.

LagPing's take

We decided to cover this story because it sits at the exact crossroads of AI capability and real-world security consequence that our readers care about most. Post-quantum cryptography isn't abstract — it's the foundation being laid right now for how sensitive data will be protected in a world where quantum computers eventually become viable attack tools. When an AI system meaningfully accelerates a finding that causes an algorithm to be withdrawn from a national standards process, that's not just a cryptography story. It's a story about how AI is changing the pace and character of scientific research itself. We also think it's worth being honest about the complexity here: Anthropic's framing deserves scrutiny alongside credit, and we've tried to capture the caveats that the original reporting surfaced. We'll be watching this space closely, particularly as more details emerge about what other cryptosystems Mythos may have been tested against.

Find "Anthropic" on Amazon

As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.

You might also like