Claude Mythos identifies weaknesses in two cryptographic systems

Anthropic says the findings do not affect software currently in use, but they demonstrate an AI model making advances in a highly specialized area of cybersecurity research.

Anthropic researchers used Claude Mythos Preview to develop stronger attacks against HAWK and a seven-round version of AES-128

Anthropic researchers using Claude Mythos Preview have developed improved methods for attacking two cryptographic systems, including one being considered for protecting data from future quantum computers.

Cryptography refers to the mathematical techniques used to protect digital information. These techniques help browsers confirm that a website is genuine, encrypt information sent online and prevent unauthorized people from reading or changing communications.

Claude’s findings concern HAWK, a proposed digital signature system, and a reduced version of the Advanced Encryption Standard, or AES.

A digital signature allows a computer to verify where digital information has come from and whether it has been altered. AES performs a different function, encrypting data so that it can only be read by someone with the correct secret key. It is widely used to protect online information.

Anthropic says neither finding affects production systems. HAWK has not been deployed, while the AES research applies to a deliberately weakened version used by researchers rather than the complete encryption standard.

The significance lies in Claude identifying new mathematical weaknesses in systems that had already received extensive attention from human cryptography experts.

Claude reduces the proposed security strength of HAWK

HAWK is a candidate in a US National Institute of Standards and Technology, or NIST, process examining additional digital signature systems.

The proposed system is designed for a post-quantum world. This means it is intended to remain secure even if sufficiently powerful quantum computers are eventually developed. Such machines could potentially break several of the cryptographic methods currently used to secure digital communications.

Candidate systems such as HAWK are published for examination before they are approved and deployed. Researchers attempt to find weaknesses so that unsuitable systems can be rejected or improved before they are used to protect real information.

HAWK had passed through two rounds of expert examination over approximately two years. Working with an Anthropic researcher, Claude Mythos Preview found a way to improve the strongest known attack against it in about 60 hours.

The model identified a previously unused mathematical symmetry within the structure on which HAWK is based. Exploiting that symmetry would allow an attacker to search for the system’s secret key more efficiently.

Recovering a secret key would undermine the security provided by the signature system. Anthropic describes its finding as effectively cutting HAWK’s key strength in half, meaning that its keys would need to be doubled in size to provide the level of protection originally proposed.

Claude demonstrated the technique against the smallest version, HAWK-256. An attack previously expected to require approximately 2^64 operations was reduced to 2^38 operations, allowing the researchers to recover a key in a few hours.

The larger versions remain impractical to attack. The finding is also specific to HAWK and does not weaken other post-quantum candidates or this wider category of cryptography.

Claude completed much of the work semi-autonomously through a system in which multiple AI agents could review research, investigate ideas, perform calculations and exchange findings. Human guidance was largely limited to managing the project and suggesting tools for checking the results.

Anthropic estimates that the HAWK discovery process cost approximately $100,000 in API usage.

Research attack on reduced AES becomes up to 800 times faster

The second finding concerns AES-128, a widely used method for encrypting data.

AES protects information by applying a sequence of mathematical operations known as rounds. The complete AES-128 cipher uses 10 rounds, with every round transforming the data further.

Claude did not break that complete system. Its attack applies only to a modified version using seven rounds.

Cryptography researchers intentionally study these reduced-round versions because they are weaker and easier to examine. This helps them test new attack methods and assess how much protection the additional rounds provide.

The previous attack against seven-round AES required an impractical number of specially selected pieces of data and an extremely large amount of computing work. Claude Mythos Preview developed a new mathematical technique, which it called the Möbius Bridge, that removes one of the guesses required during the attack.

Following additional optimizations, the resulting method was estimated to be between 200 and 800 times faster than the previous strongest attack of its kind.

Although that represents a research advance, the computing requirements remain far beyond what would make the attack practical. It does not compromise the full 10-round AES system used to protect real data.

Claude produced the idea through an automated research process that allowed it to form hypotheses, run experiments and abandon approaches that did not work. After initially treating further progress against AES as unlikely, the model was instructed to continue searching for genuinely new methods.

It found the Möbius Bridge idea three days later and continued refining the attack after producing approximately one billion output tokens.

The discovery took about a week, but validating it required considerably more human involvement. Two Anthropic researchers spent several hundred hours studying the relevant cryptography and checking Claude’s work.

Human verification becomes the slower stage

The research highlights a developing imbalance between the speed at which AI models can generate possible discoveries and the time specialists require to establish whether those findings are correct.

The HAWK attack could be implemented and tested from beginning to end, making it comparatively straightforward to verify. The AES attack remains too computationally demanding to run in full, so researchers used mathematical proofs, smaller experiments and tests of individual components to examine Claude’s claims.

Anthropic followed responsible disclosure procedures, under which researchers privately notify the people responsible for a system before publishing a vulnerability. The company shared the HAWK finding with its designers in June and coordinated its release through NIST’s public mailing list. It also consulted academic, US government and industry partners.

Anthropic has partnered with ETH Zurich, Tel Aviv University and TU Berlin to develop CryptanalysisBench, a collection of cryptographic challenges for testing how well large language models can identify weaknesses in ciphers.

The company plans to continue assessing Claude’s cryptography capabilities and will hold an academic workshop to discuss how AI-generated security discoveries should be examined, verified and disclosed.

While these two findings do not affect current systems, Anthropic argues that increasingly capable models could eventually identify weaknesses with immediate real-world consequences. That prospect raises a wider question for researchers, governments and technology companies: how discoveries should be managed when AI can produce potential vulnerabilities faster than human experts can validate them.

Previous
Previous

Coursera invests $100 million in Andrew Ng’s AI learning company LearnVector

Next
Next

Hackers take more than 740,000 records from UK education and police systems