Claude Found Real Flaws In Two Cryptographic Algorithms
Anthropic says Claude Mythos Preview has found mathematical flaws in cryptographic algorithms themselves, not just mistakes in how programmers implemented them. The first result is an improved key recovery attack on HAWK, a post-quantum digital signature scheme that is one of the remaining third-round candidates in NIST's call for additional signatures. HAWK had survived two rounds of expert human review over two years, but Claude found a previously unexploited symmetry in the underlying lattice, called a nontrivial automorphism, that effectively cuts the scheme's key strength in half. Anthropic says the work took about 60 hours. The expected cost of a full key recovery attack against the small HAWK-256 parameter was thought to be 2^64 and was demonstrated to be 2^38. The attack is still exponential, not a polynomial-time break, it is specific to HAWK, and it does not affect other NIST post-quantum candidates or lattice cryptography in general. The second result targets AES-128 reduced from ten rounds to seven, a weakened variant that researchers study to measure how much safety margin the full cipher has. Claude developed a fingerprinting algorithm it called a Mobius Bridge that removes a 256-way guessing step from the previous best meet-in-the-middle attack, making it between 200 and 800 times faster. That attack assumes roughly 2^105 chosen plaintexts, so it is completely impractical. To be clear on the impact: neither result affects production systems and Anthropic says no production software will have to change. HAWK is only a candidate scheme and is not deployed, and the AES result does not break the full ten-round cipher used in the real world. Anthropic says each result cost roughly 100,000 dollars in API cost, that Claude worked mostly autonomously, and that human verification was the slow part, with two researchers spending nearly a month gaining confidence the AES method was correct.
Transcript
Anthropic said today that Claude found real mathematical flaws inside cryptographic algorithms that human experts missed for years.
HAWK is a post quantum signature candidate at NIST, not deployed anywhere. It survived two years of expert review. Then Claude halved its effective key strength in sixty hours.
The AES result attacks seven of ten rounds, a weakened variant. A new fingerprint, Mobius Bridge, makes it two hundred to eight hundred times faster, yet still completely impractical.
No production software has to change, Anthropic says. Claude worked mostly autonomously for about one hundred thousand dollars in API cost. Verification took two researchers nearly a month.
Inboxsmith helps small businesses handle calls and messages so nothing gets missed. Please like and subscribe for more news.
Sources
Every claim in this video comes from the top ranking coverage of this topic. The claims and where each one came from:
- Anthropic announced on July 28, 2026 that Claude is able to find mathematical flaws in cryptographic algorithms themselves, not just implementation errors.(Anthropic official announcement)
- HAWK is a post-quantum digital signature scheme and one of the third-round candidates in the NIST call for additional signatures.(Anthropic official announcement)
- HAWK is only a candidate signature scheme and so is not deployed.(Anthropic official announcement)
- HAWK survived two rounds of expert human review over a period of two years.(Anthropic official announcement)
- Claude Mythos Preview improved the best-known attack on HAWK in just 60 hours of work, effectively cutting its key strength in half by finding a previously unexploited symmetry in the lattice.(Anthropic official announcement)
- The AES attack works only on a modified version of AES-128 that has 7 of the full 10 rounds.(Anthropic official announcement)
- Claude developed a more sophisticated fingerprinting algorithm it called a Mobius Bridge, producing an attack that is between 200 and 800 times faster than the previous best.(Anthropic official announcement)
- The AES attack assumes the attacker can request the encryption of 2^105 chosen plaintexts and is therefore completely impractical.(Anthropic official announcement)
- Neither result has a practical impact on today's computer systems, and no production software will have to change as a result.(Anthropic official announcement)
- Mythos Preview achieved these results mostly autonomously and mostly without human intervention, and each result cost roughly $100,000 in API cost to develop.(Anthropic official announcement)
- It took two researchers nearly a month to gain confidence that the AES method Claude discovered is correct.(Anthropic official announcement)
