Cyber Security News

Claude Mythos Preview Discovers Cryptographic Weaknesses That Human Experts Missed for Years

Anthropic researchers using Claude Mythos Preview have uncovered mathematical flaws in major cryptographic algorithms that human experts failed to spot for years.

The AI found improved attacks against HAWK, a post-quantum digital signature scheme, and a reduced-round version of AES, the world’s most widely used symmetric cipher. Neither result threatens production systems today, but both mark a significant shift in how artificial intelligence can stress-test the foundations of digital security.

Cryptographic algorithms protect everything from online banking to encrypted web traffic. Digital signature schemes verify that a website is authentic, while symmetric ciphers keep data private between parties sharing a secret key.

Flaws in these systems could expose billions of users. Until now, Claude Mythos Preview had mainly found implementation bugs in cryptographic libraries coding mistakes that weaken encryption in practice. The new research shows the model can also identify weaknesses in the algorithms themselves.

Mythos Preview Discovers Cryptographic Weaknesses

The first breakthrough targets HAWK, a third-round candidate in NIST’s post-quantum cryptography competition. NIST launched the effort to replace schemes such as RSA and ECDSA, which quantum computers could eventually break.

HAWK survived two years of expert human review. Working semi-autonomously for roughly 60 hours at about $100,000 in API cost, Mythos improved the best-known key-recovery attack and effectively cut the scheme’s key strength in half.

The attack exploits a previously unused symmetry, a nontrivial automorphism, in HAWK’s lattice structure. Prior theory suggested such a symmetry could enable a faster attack, but no one had shown it existed in HAWK’s design.

The result means proposed key sizes are weaker than claimed; for example, the expected cost of breaking HAWK-256 dropped from 2^64 to 2^38 operations. Doubling key sizes would restore security but erase much of HAWK’s appeal as a compact post-quantum option.

The attack remains exponential, does not run in practical time against larger keys, and does not affect other NIST candidates or lattice cryptography in general. Anthropic shared the finding with HAWK’s authors and coordinated disclosure through NIST.

The second result improves cryptanalysis of 7-round AES-128. Full AES-128 uses 10 rounds and remains secure; researchers study reduced-round versions to probe attack techniques.

Building on meet-in-the-middle methods, Mythos invented a fingerprinting technique it called a Möbius Bridge. The method eliminates one guessing step that previously required checking 256 values, yielding an attack 200 to 800 times faster than the prior best, depending on measurement.

Discovery was almost fully autonomous after light human prompting over several days. Researchers then spent hundreds of hours validating the claims.

Anthropic has also seen promising early results against reduced-round LEA and Serpent, plus smaller gains on Salsa20, Poseidon, and SHA-1. To help the field track progress, the company partnered with ETH Zurich, Tel Aviv University, and the University of Haifa on CryptanalysisBench, a new benchmark for evaluating language models on cryptanalysis.

These findings do not require changes to deployed software. HAWK is only a candidate, and the AES attack does not break the full cipher. They do show that frontier AI can accelerate the adversarial review cryptography has always relied on finding weaknesses before schemes protect real users.

As models grow more capable, human experts may increasingly focus on verifying AI-generated research. Anthropic has begun broader audits and plans academic workshops on the role of language models in security research. Used responsibly, such tools could strengthen the algorithms that safeguard the internet for everyone.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago