In a development that signals both the promise and the peril of artificial intelligence in cybersecurity, Anthropic’s Mythos system has demonstrated a cryptanalytic attack potent enough to force the withdrawal of a third-round candidate from the NIST Post-Quantum Cryptography standardization process. The target, known as HAWK, was a promising signature scheme designed to withstand attacks from quantum computers. Its downfall, however, came not from a quantum adversary but from a sophisticated meet-in-the-middle attack enabled by a novel technique called the Möbius Bridge. This event marks a pivotal moment in the ongoing debate over whether large language models can genuinely advance the field of cryptanalysis or merely produce results that are impressive in a laboratory setting but limited in practical application.
How Mythos Broke HAWK: The Möbius Bridge and the Meet-in-the-Middle Revolution
The core of the Mythos breakthrough lies in a new meet-in-the-middle technique that leverages what researchers call a Möbius Bridge. This is not a reference to the famous topological surface but rather a sophisticated fingerprinting algorithm used to dramatically reduce the number of inputs required to mount a successful attack. Traditional meet-in-the-middle attacks work by splitting a cryptographic problem into two halves, solving each half independently, and then looking for a match. The bottleneck has always been the number of matches that need to be checked — the “meeting point” where the two halves converge.
What Mythos achieved, according to the Anthropic team, was a reduction in the required number of inputs to 289. To put that number in perspective, a brute-force search of 2128 possibilities is considered computationally infeasible for any foreseeable technology. At 289, the problem remains daunting but enters a realm where specialized hardware or cloud-scale distributed computing might begin to make progress. The Möbius Bridge essentially acts as a much more precise filter, allowing the attack to discard irrelevant candidate matches far earlier in the process.
Anthropic stated that this savings can reduce the time required for such attacks by 200- to 800-fold. This is not a marginal improvement; it is a shift that could transform a theoretical vulnerability into a practical one. For the HAWK signature scheme, which relied on certain algebraic structures for its security, this reduction meant that the security margin was no longer adequate. The scheme’s designers, upon reviewing the Mythos results, made the decision to withdraw HAWK from consideration, effectively acknowledging that the attack had exposed a fundamental weakness that could not be patched with minor tweaks.
What Is the Möbius Bridge Technique?
The Möbius Bridge is a fingerprinting algorithm that allows a cryptanalyst to compute a compact but highly discriminating tag for each candidate solution in a meet-in-the-middle attack. Instead of comparing full solutions, which requires massive storage and bandwidth, the bridge compares these tags. The key innovation is that the tag is computed in a way that is both efficient and collision-resistant — meaning two different solutions are extremely unlikely to produce the same tag, while two identical solutions will always produce the same tag. This allows the attack to scale to much larger problem sizes than previously possible, because the storage and communication overhead is drastically reduced.
The Weakened AES Test: A Critical Caveat
While the result against HAWK is concrete and has immediate consequences, the broader demonstration of Mythos’s capabilities comes with a significant asterisk. The team tested the system against a version of AES that was deliberately weakened to only 7 rounds. Specification-compliant AES, as Green noted, uses 10, 12, or 14 rounds depending on the key size. The difference between 7 rounds and 10 rounds is not merely incremental; it is the difference between a cipher that is vulnerable to a class of attacks and one that has been designed specifically to resist them.
The ability to produce 289 inputs in a laboratory setting is one thing. Reaching that level in a real-world attack against a full-round cipher is another entirely. Anthropic itself acknowledged that the actual speed-up is unknown when applied to standard AES, because the test was conducted on a reduced-round variant. The 200- to 800-fold improvement, while impressive, was measured against a baseline that does not represent the security level of AES in actual deployment.
What this means is that the Mythos attack, as demonstrated, does not threaten AES or any other widely deployed cryptosystem. However, it does establish a proof of concept that AI-assisted cryptanalysis can discover and exploit structural weaknesses that human researchers might miss or take much longer to find. The question is whether this capability can be scaled to full-round ciphers and to other cryptosystems like elliptic curve cryptography and RSA.
What Are the Limitations of the Mythos Cryptanalysis?
The primary limitation is that the attack was demonstrated against a weakened version of AES, not against the full cipher. Secondary limitations include the fact that the attack requires a level of computational resources that is currently beyond the reach of most organizations, and the actual speed-up relative to conventional methods is not known for full-round ciphers. Additionally, Anthropic did not report whether Mythos was used to attack more tested cryptosystems such as elliptic curve cryptography or RSA. Attack improvements against these systems would be far more impressive and would have more immediate practical implications. By achieving the most impressive result against an algorithm still in its infancy — HAWK was a third-round candidate, not a finalized standard — it is not clear how much of an advantage Mythos truly provided over conventional cryptanalysis techniques. There is no way of knowing if human researchers using traditional methods were already close to discovering the same attack.
Anthropic’s Vision: Language Models as Autonomous Cryptographic Researchers
Anthropic’s Monday blog post presented the results with a mix of technical detail and strategic vision. The company argued that the results are meaningful and could ultimately fundamentally disrupt the process of cryptanalysis. The broader argument, however, extends beyond any single attack. Anthropic is positioning Mythos as a harbinger of a new era in which language models produce novel research outputs autonomously, and human researchers become the bottleneck.
“The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up,” the company wrote. “We predict that the same will soon be true in academic cryptography research. As language models increasingly produce novel research outputs autonomously, human researchers may become bottlenecked on studying and validating these results for technical validity, novelty, and utility.”
This is a provocative claim. If true, it suggests that the role of the human cryptographer will shift from being the primary discoverer of vulnerabilities to being the validator and prioritizer of machine-generated discoveries. The implications for the pace of cryptographic research are profound. If an AI system can generate thousands of potential attack vectors per day, the rate at which cryptosystems are broken — or at least shown to be weakened — could accelerate dramatically. The NIST standardization process, which already moves at a deliberate pace, could find itself constantly playing catch-up.
The Bottleneck Problem: From Discovery to Validation
Anthropic’s insight about the bottleneck is worth examining in detail. In traditional cryptanalysis, a human researcher identifies a potential attack, works through the mathematics, implements a proof of concept, and then writes a paper. The entire process takes weeks or months. With an AI system like Mythos, the discovery phase can be compressed to hours or days. But the validation phase — verifying that the attack is correct, that it works against the full cipher, that it is not based on a flawed assumption — remains a human-intensive activity. If the rate of discovery outpaces the rate of validation, the field could become flooded with unverified claims, making it difficult to distinguish genuine breakthroughs from artifacts of the AI’s training data or optimization objectives.
The Broader Context: Post-Quantum Cryptography and the NIST Process
HAWK was a third-round candidate in the NIST Post-Quantum Cryptography standardization process, which is tasked with selecting cryptographic algorithms that can resist attacks from both classical and quantum computers. The process has been ongoing since 2016, with multiple rounds of evaluation, public comment, and refinement. HAWK was a signature scheme based on the Fiat-Shamir with Aborts framework, and it was considered a strong candidate due to its relatively small signature sizes and fast verification times.
The withdrawal of HAWK is a significant event, but it is not unprecedented. Other candidates have been withdrawn or broken during the process. What makes this case notable is the tool used to break it: an AI system rather than a human cryptographer. This raises the question of whether the NIST process, which was designed to evaluate security against human adversaries, is adequately equipped to evaluate security against AI-assisted adversaries. The standards that emerge from this process will be deployed for decades, protecting everything from financial transactions to military communications. If AI-assisted cryptanalysis can break a candidate in the third round, what does that imply for the eventual winners?
The Limits of the Demonstration: What Was Not Tested
Anthropic’s report notably did not include results for elliptic curve cryptography or RSA. These are the workhorses of modern public-key cryptography, and any attack that meaningfully reduces their security margin would be a seismic event. The absence of such results from the Mythos paper is telling. It suggests that the Möbius Bridge technique, while powerful, may be specialized to certain algebraic structures that are more common in post-quantum schemes than in classical ones. Alternatively, it may simply be that the researchers focused their efforts on the area where they expected the most dramatic results — namely, the fragile, not-yet-standardized world of post-quantum cryptography.
Attack improvements against elliptic curve cryptography or RSA would be far more impressive because those systems have been studied for decades by the world’s best cryptanalysts. The fact that Mythos found a weakness in HAWK but not in ECC or RSA could be interpreted in two ways. One interpretation is that HAWK was simply a weaker target, and Mythos did not provide a general advantage. The other interpretation is that Mythos is particularly good at finding weaknesses in algebraic structures that are not yet fully understood, and that as the system matures, it will be applied to more established targets. The truth likely lies somewhere in between, but the ambiguity underscores the need for independent verification.
The Vested Interest Problem: The Hype Cycle in AI Security
Anthropic, like all AI companies, has a vested interest in demonstrating the power of its systems. The company is in a competitive race with OpenAI, Google, Meta, and others to show that its models are not just capable of generating text and images but can also perform genuine scientific discovery. Cryptographic research is a high-visibility domain where a single breakthrough can generate headlines and attract talent and investment. The Mythos result is, from Anthropic’s perspective, a perfect demonstration: it is concrete, it has real-world consequences (the withdrawal of a PQC candidate), and it fits neatly into the narrative of AI as a transformative scientific tool.
But the same dynamic that makes the result compelling for Anthropic also makes it necessary to approach with a degree of skepticism. Providers of AI platforms have a vested interest in exaggerating the benefits of their systems. The history of AI is filled with examples of results that were later shown to be less impressive than initially claimed, or that were achieved under conditions that did not generalize to real-world problems. The Mythos result is not immune to this pattern. The use of a weakened AES variant, the lack of results against ECC and RSA, and the missing baseline comparison with conventional techniques all suggest that the full story is more nuanced than the headline suggests.
The Balanced View: What Mythos Actually Means for the Future of Cryptography
Despite the caveats, it would be a mistake to dismiss the Mythos result as mere hype. There is growing evidence that large language models can provide significant advantages in finding cryptographic weaknesses. The Möbius Bridge technique is a genuine innovation, and the fact that it was discovered by an AI system rather than a human researcher is noteworthy. The key question is not whether AI can assist in cryptanalysis — it clearly can — but rather how much of an advantage it provides, and under what conditions.
The lesson from the research is simple, but it is not the lesson that either the proponents or the skeptics might want. AI-assisted cryptanalysis remains untested in the domains that matter most — full-round AES, ECC, RSA, and the other workhorses of modern cryptography. The results against HAWK and reduced-round AES are best understood as proofs of concept, not as demonstrations of a general capability. At the same time, the trajectory is clear. The rate at which AI systems are improving suggests that it is only a matter of time before they begin to make meaningful contributions to cryptanalysis against full-strength targets. The race between securing and compromising our most vital assets is about to gain a new and powerful entrant.
For the cybersecurity community, the message is one of preparedness. The NIST process, the development of new cryptographic standards, and the training of the next generation of cryptographers must all account for the possibility that the adversary will soon be augmented by AI. The Mythos attack on HAWK is a preview of that future. It is not the future itself, but it is a clear enough picture to begin planning for it.