All news
aicybersecurityregulation

Claude AI Found New Attacks on Post-Quantum Crypto

02 Aug 2026

Anthropic says its Claude Mythos Preview model helped researchers discover two new cryptographic attacks — one against HAWK, a post-quantum digital signature scheme that had advanced fairly far in NIST's standardization process, and another against a 7-round variant of AES, the widely used symmetric cipher. Anthropic published its own account of the research, and the Cryptography Engineering blog followed on July 29, 2026, with additional analysis of the results.

What happened

HAWK is a proposed post-quantum-safe signature scheme built on the module Lattice Isomorphism Problem and related to Falcon, a scheme currently being standardized. HAWK itself was a third-round candidate in NIST's call for additional post-quantum cryptographic systems and had progressed well into the evaluation process before this discovery.

Using Claude Mythos Preview, Anthropic researchers found an improved attack that cuts HAWK's key strength roughly in half — a substantial reduction in the security margin the scheme was believed to offer. The attack was shared with HAWK's authors in June, and it reportedly produced real, working code that runs in just a few hours of wall-clock time against a weakened challenge instance. According to Anthropic, Claude arrived at this improved attack after 60 hours of work, and remarked that the ingredients involved were not exotic — calling the result "a little embarrassing for the field."

The second result targets a 7-round reduced version of AES (not the full cipher, which runs 10, 12, or 14 rounds depending on key size). Attacks on reduced-round AES aren't new — one was published as far back as 2013 — but the new attack improves the speed of the best previous attacks by 200 to 800 times, requiring 2^89 cipher operations and 2^105 chosen-plaintext encryptions under the secret key.

Anthropic states that neither vulnerability currently affects production systems. Each of the two main results reportedly cost roughly $100,000 in API costs to develop, though the report does not break down exactly what that spending purchased (compute time, number of queries, or other factors).

Anthropic also partnered with academics at ETH Zurich, Tel Aviv University, and the University of Haifa to build CryptanalysisBench, though details on how the benchmark works or how it factored into these specific results were not disclosed.

Why founders should care

These results are early and narrow — they concern reduced-round AES and a not-yet-finalized post-quantum standard, not deployed production systems. Still, several signals here are likely relevant to founders working in security, AI tooling, or infrastructure depending on emerging cryptographic standards:

  • Founders building products that depend on post-quantum cryptography should probably track NIST standardization status closely, since a scheme that had progressed well into evaluation was still found to have a meaningful weakness before finalization.
  • The ~$100,000 cost per result suggests that AI-assisted cryptanalysis of this caliber currently demands a substantial compute budget, which may put similar work out of reach for smaller teams in the near term — though costs could fall as models and techniques improve.
  • The speedups in reduced-round AES analysis, combined with the broader trend toward automated cryptanalysis, hint that AI-driven security auditing tools could become a more viable product category — an area worth watching for founders building in AI-for-security.
  • The emergence of CryptanalysisBench points to a nascent ecosystem for benchmarking AI performance in specialized technical domains, which may be of interest to founders building AI evaluation or tooling products.

What's still unclear

Several open questions remain. It's not stated whether HAWK's authors or NIST have formally responded to or validated the new attack, nor whether either result has been submitted for peer review or NIST's official evaluation process. The exact differences between "Claude Mythos Preview" and publicly released Claude models also aren't specified, making it hard to know how reproducible these results might be with generally available tools.

For now, the practical takeaway is narrower than the headline might suggest: no production systems are affected, but the direction of travel — AI models contributing directly to novel cryptographic attacks — is worth watching closely.

Sources