Anthropic's Mythos AI model helped break HAWK, a post-quantum cryptography algorithm that had reached the third round of NIST evaluation, forcing its developer to withdraw the submission on Tuesday. An Anthropic researcher with no cryptography expertise, guided by Claude Mythos Preview, produced a novel attack on HAWK in roughly 60 hours of work and about $100,000 of compute cost. The attack effectively halves the algorithm's key strength — enough for Google post-quantum expert Sophie Schmieg to declare the scheme dead.
HAWK is a digital signature scheme built on the Lattice Isomorphism Problem, a mathematical structure believed to resist quantum computing attacks. The National Institute of Standards and Technology had advanced HAWK through two rounds of adversarial testing without uncovering a fatal flaw. The third round exists specifically to catch the kind of weakness Mythos surfaced this month, and HAWK's developer pulled the submission one day after Anthropic's Monday announcement.
The technique Mythos produced targets automorphism symmetries, which underpin the best-known classical attack against the Lattice Isomorphism Problem. Mythos found a previously unknown method for finding those symmetries, breaking the algorithm by definition — in academic cryptography, an algorithm is considered broken once an adversary can derive a key faster than brute force. HAWK's weakness can be patched by doubling the key size, but the extra computation makes it uncompetitive against post-quantum signature schemes ML-DSA and FN-DSA, which NIST has already tapped as standards.
Key facts
- 01Anthropic's Mythos model helped find an attack that effectively halves HAWK's key strength, forcing its developer to withdraw the algorithm from NIST evaluation on July 29, 2026.
- 02The attack took roughly 60 hours of work and about $100,000 in compute, run by an Anthropic researcher with no cryptography expertise.
- 03HAWK had already cleared two NIST rounds of post-quantum cryptographic testing before failing the third.
- 04A separate Mythos-assisted attack on weakened 7-round AES cut required plaintext inputs from 2^105 to 2^89, a 200- to 800-fold reduction in attack time.
- 05Google PQC expert Sophie Schmieg declared HAWK dead, noting rivals ML-DSA and FN-DSA remain the competitive signature schemes.
Matthew Green, a Johns Hopkins cryptography professor, said the striking thing about the attack was not novel mathematics but the assembly of existing tools that no human had thought to combine.
Anthropic said Mythos worked semi-autonomously inside an agentic harness, taking occasional non-technical direction from the human researcher. Two separate agents pursued the improved method independently: one initially rejected it as unworkable, and the second found a way to make it work. They eventually converged, then built an end-to-end verification pipeline to prove the attack's correctness to themselves and to the operator.
Schmieg, the Google researcher, said HAWK had long been suspected of hiding weaknesses. But the specific key-halving result made the algorithm's math untenable against sitting standards.
“Basically with this paper, HAWK is dead.”— Sophie Schmieg, Google post-quantum cryptography expert
A second Mythos result targeted AES, the workhorse symmetric cipher used across the internet. The improvement here is more modest. The best prior meet-in-the-middle attack on AES required roughly 2^105 chosen plaintext inputs, a figure large enough to be infeasible in any real environment. Mythos helped identify a new technique built on a Möbius Bridge fingerprinting method, cutting the required inputs to 2^89 — a 200- to 800-fold reduction in attack time, per Anthropic.
The caveats matter. The AES version tested used 7 rounds, while specification-compliant AES uses 10, 12, or 14 rounds depending on key size. Both attacks were run against weakened "challenge instances" that specification authors provide for peer review, not the production versions of the ciphers. Neither result breaks any cryptosystem in deployment today, and 2^89 inputs remain far out of reach of any real-world adversary. Anthropic spells out most of these limits explicitly.
The company argues the broader implication is that language models are entering cryptanalysis the way they entered vulnerability research.
“The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up.”— Anthropic, company statement
Skeptics will note that Anthropic has commercial incentives to overstate what Mythos accomplished, and Ars Technica's Dan Goodin flagged an obvious gap: the report does not describe whether Mythos was turned loose on more heavily studied systems like elliptic curve cryptography or RSA. Meaningful attack improvements against those would be far more impressive than a result on a young NIST candidate. It is also possible that human cryptanalysts using conventional methods were already closing in on the same HAWK weakness. Mythos remains restricted to a small group of trusted users, so independent replication is limited.
Still, the practical outcome is unambiguous: a NIST-track post-quantum signature scheme is off the board, and the fastest path to killing it ran through an AI model rather than a human research group. That reorders the incentives on both sides of the cryptography stack. Defenders who rely on years-long adversarial review to shake out weaknesses now face review cycles that can be compressed into weeks of compute. Vendors of AI models built for security research — Anthropic today, others soon — will treat cryptanalysis wins as anchor demos for enterprise buyers. And NIST, which has spent nearly a decade winnowing post-quantum candidates, may find its remaining shortlist tested on a faster clock than it planned.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




