Anthropic
Claude AI finds new cryptographic weaknesses, Anthropic says
The model cut HAWK's effective key size in half and broke reduced-round AES hundreds of times faster than known methods.
The answer
Anthropic's Claude Mythos found new attacks on several cryptographic schemes.
What happened: Anthropic said its Claude Mythos Preview model discovered new attacks against several cryptographic schemes, according to research published 28 July 2026.
The numbers: Against the post-quantum signature scheme HAWK, the model halved the effective key size after about 60 hours of work and roughly $100,000 in API cost. Against AES reduced to 7 rounds, it produced an attack 200 to 800 times faster than the best previously known, using 3 days of autonomous work, 1 billion output tokens and about $100,000.
The details: The model also broke LEA reduced to 13 rounds with a practical attack needing fewer than 2^30 plaintexts in under an hour, and achieved full key recovery on Serpent-128 reduced to 6 rounds. It made only small improvements, under 10 times, against Salsa20, Poseidon and SHA-1.
The catch: Full-strength AES was not broken. Reduced-round variants are how cryptographers measure a cipher's safety margin, not real-world vulnerabilities on their own.
Who's affected: Human researchers still had to check the work. Verifying the AES result took two researchers nearly a month, several hundred hours, during which they had to learn cryptography themselves. The HAWK result was checked by one researcher with a theoretical computer science background.
The context: The HAWK authors were notified in June. Disclosure of the findings was coordinated with NIST, the US government and industry partners.
In their words: Anthropic said: "Without secure cryptographic systems like these, your email, online banking, and other internet use would be open to cybercriminals, who could intercept or modify your communications."
Why it matters: The results show an AI model producing original findings in one of the most demanding fields of mathematics and security, rather than just applying known techniques.
What's next: Anthropic gave no timeline for further cryptographic testing beyond the disclosed coordination with NIST and industry partners.
Sources
- Discovering cryptographic weaknesses with Claude — Anthropic, 28 July 2026