cognitive cybersecurity intelligence

News and Analysis

Search

Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years

Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years

Anthropic researchers using Claude Mythos Preview have uncovered mathematical flaws in major cryptographic algorithms that human experts failed to spot for years.

The AI found improved attacks against HAWK, a post-quantum digital signature scheme, and a reduced-round version of AES, the world’s most widely used symmetric cipher. Neither result threatens production systems today, but both mark a significant shift in how artificial intelligence can stress-test the foundations of digital security.

Cryptographic algorithms protect everything from online banking to encrypted web traffic. Digital signature schemes verify that a website is authentic, while symmetric ciphers keep data private between parties sharing a secret key.

Flaws in these systems could expose billions of users. Until now, Claude Mythos Preview had mainly found implementation bugs in cryptographic libraries coding mistakes that weaken encryption in practice. The new research shows the model can also identify weaknesses in the algorithms themselves.

Mythos Preview Discovers Cryptographic Weaknesses

The first breakthrough targets HAWK, a third-round candidate in NIST’s post-quantum cryptography competition. NIST launched the effort to replace schemes such as RSA and ECDSA, which quantum computers could eventually break.

HAWK survived two years of expert human review. Working semi-autonomously for roughly 60 hours at about $100,000 in API cost, Mythos improved the best-known key-recovery attack and effectively cut the scheme’s key strength in half.

The attack exploits a previously unused symmetry, a nontrivial automorphism, in HAWK’s lattice structure. Prior theory suggested such a symmetry could enable a faster attack, but no one had shown it existed in HAWK’s design.

The result means proposed key sizes are weaker than claimed; for example, the expected cost of breaking HAWK-256 dropped from 2^64 to 2^38 operations. Doubling key sizes would restore security but erase much of HAWK’s appeal as a compact post-quantum option.

The attack remains exponential, does not run in practical time against larger keys, and does not affect other NIST candidates or lattice cryptography in general. Anthropic shared the finding with HAWK’s authors and coordinated disclosure through NIST.

The second result improves cryptanalysis of 7-round AES-128. Full AES-128 uses 10 rounds and remains secure; researchers study reduced-round versions to probe attack techniques.

Building on meet-in-the-middle methods, Mythos invented a fingerprinting technique it called a Möbius Bridge. The method eliminates one guessing step that previously required checking 256 values, yielding an attack 200 to 800 times faster than the prior best, depending on measurement.

Discovery was almost fully autonomous after light human prompting over several days. Researchers then spent hundreds of hours validating the claims.

Anthropic has also seen promising early results against reduced-round LEA and Serpent, plus smaller gains on Salsa20, Poseidon, and SHA-1. To help the field track progress, the company partnered with ETH Zurich, Tel Aviv University, and the University of Haifa on CryptanalysisBench, a new benchmark for evaluating language models on cryptanalysis.

These findings do not require changes to deployed software. HAWK is only a candidate, and the AES attack does not break the full cipher. They do show that frontier AI can accelerate the adversarial review cryptography has always relied on finding weaknesses before schemes protect real users.

As models grow more capable, human experts may increasingly focus on verifying AI-generated research. Anthropic has begun broader audits and plans academic workshops on the role of language models in security research. Used responsibly, such tools could strengthen the algorithms that safeguard the internet for everyone.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts