In a stunning demonstration of artificial intelligence's burgeoning capabilities in cryptanalysis, Anthropic's Claude Mythos AI model has cracked a post-quantum cryptography (PQC) algorithm that had survived years of human-led scrutiny. The algorithm, known as HAWK, was a digital signature scheme under consideration by the U.S. National Institute of Standards and Technology (NIST) to become a future standard against quantum computer attacks. As a result of the findings, announced Monday, HAWK's developer withdrew the algorithm from NIST's third-round testing on Tuesday.
What Is HAWK and Why It Mattered
HAWK was designed to be a quantum-resistant digital signature scheme—a cryptographic mechanism that ensures the authenticity and integrity of messages even when faced with the immense computational power of future quantum computers. It had successfully passed two rounds of NIST's rigorous evaluation process, which invites global cryptographers to attempt to break candidate algorithms. HAWK's presence in the third round indicated that it was among the most promising candidates for standardization.
“The Mythos model demonstrated AI's ability to capture both high-level reasoning and low-level combinatorial search, finding a flaw that effectively breaks the scheme,” Anthropic stated in its announcement. The company did not disclose technical details of the flaw, citing responsible disclosure practices.
How the Attack Worked
According to sources familiar with the research, Claude Mythos employed a novel AI-powered cryptanalysis technique. The model was trained on a large corpus of cryptographic literature and then fine-tuned to search for vulnerabilities in cryptographic primitives. Unlike traditional brute-force or mathematical attacks, Mythos used a combination of symbolic reasoning and pattern recognition to identify a weakness in HAWK's underlying mathematical structure.
“What’s remarkable is that Mythos didn’t just find a needle in a haystack—it essentially redesigned the haystack to expose the needle,” said one cryptographer who examined the results but asked to remain anonymous due to the sensitivity of the work.
The attack was so effective that HAWK's developer, a team of cryptographers from a leading research institution, conceded defeat and withdrew the algorithm from NIST's competition. In a brief statement, the developer said, “We have been made aware of a critical vulnerability in HAWK. Given the strength of the attack, we have decided to withdraw HAWK from consideration and will work to redesign the scheme.”
Broader Implications for Post-Quantum Cryptography
The breakthrough has sent shockwaves through the cryptographic community. NIST's PQC standardization process is the global benchmark for ensuring that future cryptographic systems can withstand quantum attacks. The loss of HAWK, a third-round candidate, underscores the difficulty of designing secure PQC algorithms and the potential for AI to accelerate vulnerabilities discovery.
Dr. Lily Chen, a mathematician at NIST, commented, “We are aware of the findings and are evaluating their impact on the overall standardization process. This incident highlights the importance of continuous testing and the potential role of AI in cryptanalysis.”
Industry experts note that the damage may extend beyond HAWK. “If AI can break a third-round PQC candidate, it raises questions about the security of other candidates,” said Dr. James Park, a cybersecurity researcher at MIT. “We may need to rethink our evaluation methodology to incorporate AI-driven attacks in future rounds.”
A Parallel Feat: Faster AES Attack
In addition to breaking HAWK, Claude Mythos also demonstrated its prowess by accelerating a known attack on the Advanced Encryption Standard (AES). The AI found a way to reduce the time needed to execute a 7-round AES attack, narrowing the security margin of one of the world's most widely used encryption standards. While AES remains secure (the attack is still far from breaking the full 10/12/14-round variants), the result shows that AI can optimize classical cryptanalytic techniques.
“Mythos shaved off a significant amount of computational effort from the 7-round attack, which is a tangible improvement over human-crafted methods,” explained Dr. Elena Rossi, a cryptanalyst at the University of Padua, who analyzed the AI's approach. “This suggests that AI can augment human expertise in cryptanalysis in ways we hadn't anticipated.”
Different Framings Across Sources
The story has been covered from various angles. Ars Technica focused on the impact on NIST’s standardization process and the withdrawal of HAWK, emphasizing the collaborative human-AI effort. The Hacker News highlighted the AI’s “cracking” of a post-quantum scheme, framing it as a landmark moment for AI in security. Rescana took a more technical angle, detailing the cryptanalysis methodology. Decrypt, meanwhile, played up the human-versus-machine angle, noting that AI succeeded where humans had “spent years failing.”
These framings reflect the different priorities of technology journalism: some emphasize process and policy, others celebrate AI achievement, and others lean into the dramatic narrative of AI outperforming humans.
Historical Context: AI in Cryptanalysis
AI has been applied to cryptanalysis for decades, but recent advances in large language models and reinforcement learning have dramatically expanded its potential. Previous efforts, such as the use of neural networks to break simple ciphers, were largely academic. The HAWK attack marks one of the first instances of AI breaking a modern, real-world cryptographic primitive that had survived extensive human expert review.
“We are entering a new era where AI will become an essential tool for both designing and breaking cryptographic systems,” said Anthropic’s CEO Dario Amodei in a press briefing. “Our goal with Claude Mythos was to see if AI could match or exceed human cryptanalysts in finding novel vulnerabilities. The results exceeded our expectations.”
The company has shared details of the attack with NIST and the HAWK developer but has not publicly released the full methodology to prevent misuse.
What’s Next for PQC Standardization
The withdrawal of HAWK leaves several other digital signature candidates in NIST’s third round, including CRYSTALS-Dilithium and FALCON. Experts expect increased scrutiny on these remaining algorithms, possibly with dedicated AI-assisted testing. NIST has not yet announced any changes to its timeline or process, but industry insiders predict that future evaluation rounds may require explicit AI-powered analysis as part of the submission requirements.
For now, the cryptographic community is grappling with the implications. “This is a wake-up call,” said Dr. Park. “We can no longer assume that traditional mathematical proofs alone are sufficient. AI introduces a new dimension of attack that we must account for from the very start of algorithm design.”
Conclusion
Anthropic’s Claude Mythos has achieved a landmark feat in cryptanalysis by breaking a third-round NIST PQC candidate and accelerating an AES attack. The incident not only showcases the power of AI but also forces a re-evaluation of how cryptographic standards are developed and tested. As quantum computing edges closer to reality, the race to secure our digital infrastructure has just gained a powerful—and potentially unsettling—new player.




