Claude AI cracks post-quantum security test in under four hours

Anthropic's Claude AI autonomously cracks a post-quantum encryption test and discovers a faster attack on AES-128, raising urgent cybersecurity questions.

By Central
Claude AI uncovers hidden vulnerabilities in HAWK-256 and AES-128, demonstrating AI's growing role in cryptanalysis.
Highlights
  • Claude recovered a full cryptographic key from HAWK-256 in under four hours, exploiting a hidden symmetry.
  • The AI discovered a 200-to-800 times faster attack on a reduced-round version of AES-128 by eliminating a key guessing step.
  • Anthropic responsibly published findings on weakened algorithms, but the results highlight AI's potential to disrupt cybersecurity.

In a striking demonstration of artificial intelligence’s escalating capabilities in advanced mathematics and cryptography, Anthropic’s Claude AI has cracked a post-quantum encryption test scheme and discovered a 200 to 800 times faster attack on a reduced-round version of AES-128, the backbone of modern digital security. The breakthrough, achieved using the company’s Mythos Preview AI model, saw the system autonomously recover a full cryptographic key in under four hours, exposing hidden vulnerabilities that had eluded human researchers. While Anthropic stresses that neither finding poses an immediate threat to production software, the results mark a profound shift in how encryption schemes may be evaluated and stress-tested before deployment, and they raise urgent questions about the role of advanced AI in the future of cybersecurity.

The HAWK-256 Attack: A Seven-Round Collapse in Under Four Hours

Claude targeted a research version of HAWKa-256, a digital signature system designed specifically to remain secure against the future threat of quantum computers. HAWK-256 is part of a new generation of post-quantum cryptography currently being evaluated by the National Institute of Standards and Technology (NIST) as it works toward standardization. The version Claude attacked was a deliberately weakened research instance with only seven rounds of its lattice-based algorithm, rather than the full specification intended for production use.

The AI’s achievement was not merely computational brute force. Claude uncovered a hidden symmetry within the HAWK-256 lattice-based algorithm, a structural flaw that drastically reduced the system’s effective key strength. Exploiting this symmetry, the model performed a full key recovery in approximately 3 hours and 42 minutes, running on a 96-core server. For context, conventional methods would have required weeks or months of computation on equivalent hardware to achieve the same result, assuming the vulnerability was even known to exist.

The seven-round limitation is critical. Production HAWK-256 will employ a higher number of rounds specifically to defend against exactly this type of reduced-round attack. Anthropic’s work therefore does not compromise the real-world security of systems that follow the final, standardized specification. However, the speed and autonomy with which Claude identified and exploited the structural weakness demonstrates a new paradigm for cryptographic analysis.

Claude’s AES-128 Breakthrough: Eliminating the 256-Way Guess

Separately, the Mythos Preview AI model found a novel way to streamline an attack on a seven-round version of AES-128, the encryption standard that secures everything from web traffic to government communications. Full AES-128 performs 10 rounds of complex mathematical transformations. Claude’s discovery focused on eliminating a computationally expensive 256-way guessing step that had previously been a necessary part of mounting an effective reduced-round attack.

By removing this step, Claude achieved an attack that is 200 to 800 times faster than previously known methods for the same reduced-round scenario. This is a significant improvement in cryptanalytic efficiency, even if it applies only to a version of AES that is not used in practice. The finding is analogous to discovering a faster way to pick a lock that uses only six of its ten pins — academically fascinating, strategically important, but not a direct threat to a door secured with all ten.

The discovery highlights how AI can systematically explore vast mathematical spaces that humans cannot practically navigate. Traditional cryptanalysis relies on human intuition, pattern recognition, and years of domain expertise. Claude demonstrated that a well-trained model can autonomously identify algorithmic shortcuts and structural symmetries that would require an exceptional human cryptographer years to find, if they found them at all.

What is the practical significance of reduced-round attacks?

Reduced-round attacks are a standard tool in cryptographic research. They allow cryptographers to measure the security margin of an algorithm by testing how many rounds can be compromised before the full cipher becomes computationally secure. Showing that Claude can break a seven-round version of AES-128 with vastly improved efficiency does not threaten real AES-128 deployments, but it provides a benchmark for the algorithm’s true resilience. It also demonstrates that AI models can uncover attack vectors that humans might overlook, which is precisely why NIST and other standards bodies encourage rigorous testing of reduced-round variants before finalizing production specifications.

Autonomous Discovery with Human Oversight: The $200,000 Research Campaign

Anthropic revealed that Claude conducted the bulk of the research autonomously. Human involvement was limited to high-level oversight and verification of the results. The total cost for both projects reached approximately $200,000 in API usage — roughly $100,000 per cryptographic attack. This figure is strikingly modest compared to the resources typically required for cutting-edge cryptanalytic research. A university team might spend months and hundreds of thousands of dollars in labor and compute time to achieve comparable results, if they could achieve them at all.

The economics of this breakthrough are significant. If an AI model costing a few hundred thousand dollars in compute can match or exceed the output of a team of elite cryptographers working for a year, the implications for the field are profound. Research institutions, standards bodies, and intelligence agencies will need to reconsider how they conduct cryptographic evaluation. The traditional model of human experts proposing, testing, and peer-reviewing new encryption schemes may need to incorporate AI-driven analysis as a standard, mandatory step before any algorithm is deemed ready for deployment.

Anthropic framed Claude’s work as a positive development for the security community. The company stated explicitly that neither result threatens production software, emphasizing that the HAWK-256 test and the AES-128 findings are used to gauge cryptographic resilience. The ability to discover weaknesses humans have overlooked is framed not as a danger, but as an essential capability for evaluating new encryption schemes before they are deployed into real-world systems.

Post-Quantum Cryptography: Why Timing Matters

The timing of Claude’s achievement is not coincidental. The entire field of post-quantum cryptography is gaining critical attention as NIST moves toward final standardization of quantum-resistant algorithms. The agency has been running a multi-year process to select and standardize cryptographic algorithms that can withstand attacks from future quantum computers, which would break current public-key systems like RSA and elliptic-curve cryptography with relative ease.

HAWK-256 is one of the candidates in this process. The fact that an AI model could discover a hidden symmetry in a reduced-round version of the algorithm, and exploit it to recover a key in hours, is exactly the kind of stress test that NIST and the cryptographic community need. It is better to find these weaknesses now, during the evaluation phase, than after the algorithm has been deployed in billions of devices worldwide.

The discovery also raises a deeper question: if Claude can find vulnerabilities in reduced-round variants today, what will future, more powerful AI models be capable of against full-round production algorithms? The trajectory of AI capability suggests that today’s modest demonstrations may be precursors to far more potent cryptanalytic tools. Standards bodies must account for this exponential improvement in AI capability when setting security margins for the algorithms of tomorrow.

How does Claude’s approach differ from traditional cryptanalysis?

Traditional cryptanalysis relies on human researchers developing mathematical theories and testing them through iterative experiments. Claude approached the problem from the opposite direction. The AI was trained on vast datasets of mathematical structures and cryptographic primitives, enabling it to explore the search space of attack vectors without predefined hypotheses. In the case of HAWK-256, it identified the hidden symmetry not because a human told it to look for symmetry, but because the model’s internal representations allowed it to recognize patterns invisible to human inspection. This capability is not merely a speedup of existing methods; it represents a fundamentally different methodology for discovering vulnerabilities.

Implications for the Cybersecurity Industry

For the cybersecurity industry, Claude’s results are a double-edged sword. On one hand, the ability to autonomously and inexpensively test encryption schemes offers an enormous defensive advantage. Organizations can now consider running AI-driven audits on their cryptographic implementations before deployment, potentially catching subtle flaws that human reviewers would miss. The cost of such audits, measured in tens or hundreds of thousands of dollars in API compute, is trivial compared to the cost of a major security breach.

On the other hand, the same capability is available to adversaries. State-sponsored hacking groups, organized cybercriminal enterprises, and intelligence agencies all have access to advanced AI models. If Claude can find hidden symmetries in a lattice-based post-quantum algorithm, it is reasonable to assume that other actors with access to equivalent or superior models are conducting similar research. The democratization of cryptanalytic power is underway, and the defensive community must prepare for a world where attackers can discover novel vulnerabilities faster than ever before.

This prospect underscores the urgency of cryptographic agility — the ability to quickly replace compromised algorithms with secure alternatives. Systems that rely on a single, static encryption standard are increasingly vulnerable to AI-driven discovery. The future of cybersecurity will likely involve more frequent algorithm rotation, more sophisticated monitoring for unusual mathematical patterns, and a closer partnership between human cryptographers and AI analysis tools.

The Broader Pattern: AI as a Research Engine

Anthropic’s announcement fits into a broader pattern of AI models making surprising contributions to mathematics and the hard sciences. In recent months, models like Claude and Google DeepMind’s AlphaFold have demonstrated that AI can generate novel mathematical proofs, predict protein structures with unprecedented accuracy, and now, discover cryptographic vulnerabilities. These are not narrow, pattern-matching exercises; they involve genuine insight into complex, abstract systems.

The key difference in the cryptographic domain is the direct and immediate real-world impact. A novel protein structure prediction may accelerate drug discovery by years. A novel cryptographic attack can compromise the security of every system that uses the affected algorithm. The margin for error is vanishingly small. This places a premium on rigorous verification, transparent methodology, and responsible disclosure — all of which Anthropic appears to have followed in publishing its findings.

The cryptographic research community now faces a choice. It can embrace AI as a powerful new tool for hardening encryption standards, or it can treat AI-driven discoveries as anomalies to be reluctantly acknowledged. The open question is no longer whether AI can contribute to cryptanalysis; it is how quickly the field can adapt its processes, standards, and workforce to integrate AI as a core component of cryptographic evaluation.

What HAWK-256 and AES-128 Tell Us About the Road Ahead

The specific technical details of Claude’s attacks are important, but the broader lesson is more significant. Post-quantum cryptography is entering a new phase where the algorithms that survive must prove their resilience not only against known mathematical attacks, but against the unknown capabilities of future AI systems. The seven-round HAWK-256 attack demonstrates that even algorithms built on well-understood lattice problems can harbor hidden structural weaknesses that an AI can discover.

For organizations already planning their migration to post-quantum cryptography, the message is clear: the evaluation process is not over. Standards published by NIST should be seen as starting points, not endpoints. Independent verification using AI-driven analysis should become standard practice before any algorithm is deployed in mission-critical systems. The cost of that analysis, while not trivial, is negligible compared to the cost of a catastrophic security failure.

The AES-128 discovery, while less immediately pressing, carries its own warning. AES is one of the most studied cryptographic algorithms in history. Human cryptographers have spent decades analyzing its properties and searching for weaknesses. The fact that an AI could find a substantially faster attack on a reduced-round variant suggests that even well-trodden cryptographic ground may contain surprises. This should motivate renewed attention to the security margins of all widely deployed encryption standards, not just those being designed for the quantum era.

Claude’s performance also raises the question of scale. The model ran on a 96-core server and required $200,000 in API costs. Future models, running on more powerful hardware and trained on even larger datasets, will achieve better results at lower cost. The trajectory points toward AI systems that can, as a matter of routine, evaluate entire families of encryption algorithms, searching for vulnerabilities that would take human teams years to find. The cryptographic community must build the infrastructure to handle this incoming wave of automated discovery, ensuring that vulnerabilities are reported, analyzed, and patched before they can be exploited in the wild.

Anthropic has positioned its work as a service to the security community, and that framing is accurate. The company chose to attack research-grade, reduced-round versions of algorithms, not production systems. The results were published openly, allowing other researchers to verify and build upon the findings. This responsible approach sets a welcome precedent for how AI companies should handle cryptographic discoveries. Whether that precedent will be followed by other actors, state and non-state alike, remains an open and unsettling question.

The era of AI-assisted cryptanalysis is here. Claude has demonstrated that the technology works, that it is cost-effective, and that it can uncover hidden weaknesses in algorithms designed by the brightest human minds. The next phase will test whether the security community can adapt quickly enough to turn this new capability into a defensive advantage rather than a vulnerability waiting to be exploited.

Share This Article