Anthropic’s Mythos Model Cracks Key Crypto Weaknesses

Anthropic's Claude Mythos Preview model discovers mathematical weaknesses in HAWK and AES, challenging assumptions about cryptographic security.

By Central
Anthropic's Mythos model found a flaw in HAWK in 60 hours at a cost of $100,000.
Highlights
  • Mythos found an improved attack on the HAWK post-quantum signature scheme in just 60 hours.
  • The model also developed a novel attack on a reduced version of the Advanced Encryption Standard.
  • These findings suggest that AI-assisted analysis may become a prerequisite for future cryptographic standards.

Artificial intelligence has discovered mathematical weaknesses in two cornerstone cryptographic algorithms, demonstrating that large language models can now perform original cryptanalytic research that previously required years of specialized human expertise. Anthropic’s Claude Mythos Preview model developed an improved attack on the post-quantum signature scheme HAWK and a novel attack on a reduced version of the Advanced Encryption Standard (AES), the world’s most widely used symmetric encryption standard for digital data. While neither finding affects systems currently in use today, the results fundamentally challenge long-held assumptions about the security of cryptographic primitives and raise urgent questions about how rapidly advancing AI capabilities could reshape the landscape of digital security.

AES encrypts nearly everything people do online, from banking transactions and private messages to government communications and medical records. HAWK is a candidate in an ongoing standardization process run by the U.S. National Institute of Standards and Technology (NIST) designed to create signature schemes that remain secure even against future quantum computers. Anthropic stated in its research disclosure that neither finding threatens systems in active deployment today, but the implications of AI models discovering cryptographic weaknesses at this speed and cost represent a paradigm shift in how the security community must think about algorithmic trust.

Mythos Found the HAWK Attack in 60 Hours for $100,000 in Compute Costs

HAWK currently stands as one of the remaining schemes in the third round of NIST’s competition for additional post-quantum signatures. These schemes are designed specifically to withstand cryptanalytic attacks from future quantum computers, which pose a fundamental threat to the RSA and elliptic curve cryptography that underpin much of today’s internet security infrastructure. Human cryptographers had reviewed HAWK for over two years, subjecting it to rigorous mathematical analysis. Mythos Preview found an improved attack in just 60 hours.

The attack exploits a previously undetected symmetry in the mathematical lattice upon which HAWK’s security relies. Lattice-based cryptography, considered one of the most promising post-quantum approaches, derives its hardness from the difficulty of solving certain problems involving high-dimensional lattices. Mythos worked semi-autonomously within a multi-agent system to discover this flaw. One agent initially attempted to dismiss the idea as infeasible, according to Anthropic’s internal report on the findings. A second agent, however, identified a way to fully exploit the symmetry, demonstrating the power of multi-agent architectures to overcome individual model limitations through collaborative reasoning.

The human researcher supervising the effort had a background in theoretical computer science but was not an expert in lattice-based cryptography. Their role was largely limited to project management, monitoring progress, and making high-level strategic decisions about which avenues to pursue. The API costs for this single experiment totaled approximately $100,000, a figure that underscores how accessible sophisticated cryptanalytic capabilities are becoming. A human-led research effort of comparable depth would typically require months of work by multiple expert cryptographers and significantly higher costs.

What Makes the HAWK Attack Significant for Post-Quantum Cryptography?

The HAWK attack matters because it targets a scheme that has undergone extensive peer review by the world’s leading cryptographers. NIST’s ongoing post-quantum standardization process is arguably the most rigorous cryptographic vetting exercise in history, involving multiple rounds of public submissions, community analysis, and expert evaluation. That an AI model could find a previously unknown weakness after only 60 hours of computational work suggests that the human review process, however thorough, may have blind spots that AI systems can systematically identify.

The specific nature of the vulnerability also carries broader implications. Lattice-based cryptography has emerged as the leading candidate for post-quantum security precisely because lattice problems have proven resistant to both classical and quantum attack. The HAWK weakness demonstrates that even within this trusted mathematical framework, subtle structural properties can create exploitable vulnerabilities that automated systems may detect more reliably than human analysts.

Post-quantum cryptography represents a multibillion-dollar transition for global digital infrastructure. Governments, financial institutions, and technology companies are racing to migrate their systems before quantum computers reach sufficient power to break current encryption. The discovery that AI models can independently find weaknesses in proposed quantum-resistant algorithms adds a new variable to these migration timelines. Standards bodies may need to consider AI-assisted cryptanalysis as a required component of the vetting process going forward.

Mythos Initially Refused the AES Task Before Finding a Novel Attack Method

The AES attack tells a different but equally revealing story about AI capabilities. Mythos found the attack on a reduced version of AES-128 almost entirely on its own, according to Anthropic’s account. A researcher built a computational scaffold that allowed the model to form cryptographic hypotheses and test them through experimental verification. Mythos then developed an entirely new fingerprinting method that Anthropic has named the “Möbius Bridge.”

This method removes one of the guesses that an attacker must typically make during cryptanalysis, improving on the best previously known attacks by a factor of 200 to 800. The improvement factor varies depending on the specific parameters of the reduced-round version under attack. For security practitioners, improvements of this magnitude are remarkable. They typically require either deep theoretical insight or extensive computational brute force. The Möbius Bridge combines both, representing a genuinely novel cryptanalytic technique discovered by an AI system.

What Is the Möbius Bridge and How Does It Work in Cryptographic Attacks?

The Möbius Bridge is a fingerprinting technique that reduces the number of unknown variables an attacker must resolve when targeting a reduced version of AES-128. In simplified terms, cryptanalysis of AES often involves making educated guesses about internal state values and then checking whether those guesses are consistent across multiple rounds of encryption. The Möbius Bridge exploits mathematical relationships between round outputs to eliminate one entire dimension of guessing, effectively halving the search space in a way that cascades into significant performance improvements.

The technique works by identifying correlations between bits across different rounds that were previously considered independent. By modeling these correlations as a continuous transformation, analogous to the twist in a Möbius strip, the method creates a bridge between internal states that conventional cryptanalysis treats as separate. This is the kind of elegant mathematical insight that human cryptographers might take months or years to develop. The model generated it as part of an automated exploration process.

Human Prompting and Refusal: When Mythos Said No to Cryptanalysis

The path to the AES finding was not straightforward. The model initially refused to tackle the problem because it considered further improvements impossible. In a strikingly human moment, Mythos wrote that “If you want a different outcome, the target has to change … AES-128 r5/r6 is just genuinely hard.” This refusal reflects a sophisticated understanding of the difficulty landscape in cryptanalysis. The model recognized that standard approaches were exhausted and judged the remaining possibilities as insufficient.

Only after the human researcher encouraged it to look for “genuinely novel ideas” did Mythos begin pursuing the creative approaches that eventually led to the Möbius Bridge. Over three days of continuous computation, the model generated several hundred million tokens of reasoning and received only three more substantive prompts from the human supervisor. One of those prompts simply read, “gain we are not looking for low hanging fruit, we want proper research to find genuinly [sic] hard findings.”

The interaction between model and researcher reveals an emerging workflow for AI-assisted scientific discovery. The model handles the exploration of the solution space, generates hypotheses, tests them, and iterates at a scale no human could match. The human provides high-level direction, encourages creative divergence when the model gets stuck, and validates results. This division of labor produced cryptanalytic findings that neither party could have achieved alone.

How Much Did the AES Attack Cost and How Was It Validated?

The AES experiment also cost approximately $100,000 in API fees for roughly 1 billion tokens of computation. To put that in perspective, a billion tokens represents a volume of internal text generation equivalent to several thousand books. The model was effectively reading and writing its own research library in real-time as it explored cryptographic structures.

Human researchers who were not cryptography experts then spent several hundred hours checking the validity of the model’s results. This validation step proved essential. AI models can produce plausible-sounding but incorrect mathematical reasoning, and cryptanalytic findings require extraordinary precision. A single bit-level error in an attack can render the entire result meaningless. The fact that Anthropic’s non-expert researchers could verify the findings suggests that the model’s internal reasoning was sufficiently clear and well-structured to allow external validation.

The total cost of under $200,000 combined across both experiments stands in sharp contrast to traditional cryptanalytic research. Major cryptanalysis projects at universities or national laboratories typically require grant funding in the millions of dollars, years of specialized training for researchers, and substantial infrastructure. The bar for conducting state-of-the-art cryptanalytic research is dropping rapidly.

Anthropic Shared the Findings and Still Restricts Access to Mythos Preview

Anthropic shared the cryptographic findings in advance with the U.S. government and industry partners. This kind of responsible disclosure is standard practice in the security community, giving affected parties time to assess and respond to vulnerabilities before public release. Anthropic also coordinated disclosure of the HAWK weakness directly with the scheme’s academic authors, allowing them to analyze the attack and prepare countermeasures.

Mythos Preview itself remains unavailable to the public. This restricted access mirrors a broader industry debate about how to balance the benefits of AI capabilities with the risks they pose. A model that can discover cryptographic weaknesses could be used to strengthen security or to undermine it, depending on the intentions of the user. Anthropic has chosen to limit access to the model while continuing to research its capabilities and limitations.

What Is CryptanalysisBench and How Does It Evaluate AI Cryptographic Abilities?

Working with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa, Anthropic developed a new benchmark called CryptanalysisBench. This benchmark allows researchers to systematically evaluate the cryptanalytic abilities of language models in a standardized way. CryptanalysisBench provides a controlled environment where different models can be tested against known cryptographic problems, with clear metrics for success and failure.

The creation of CryptanalysisBench represents an acknowledgment that the field needs rigorous evaluation frameworks for AI cryptanalytic capabilities. As these models become more powerful, the security community requires tools to understand what they can and cannot do. Standards bodies may eventually require cryptanalysis benchmark scores as part of their evaluation criteria for new algorithms.

What the Mythos Findings Mean for AI Security and Cryptographic Standards

The Mythos Preview results carry implications that extend far beyond the specific algorithms attacked. They demonstrate that large language models, when given appropriate computational resources and scaffolding, can produce original cryptanalytic research of genuine value. This is not pattern matching or knowledge retrieval. The model discovered mathematical structures that human experts had missed after years of analysis.

For the cryptography community, these findings suggest that the traditional process of algorithmic vetting must evolve. Human peer review remains essential, but it may no longer be sufficient. Future cryptographic standards may require AI-assisted analysis as a prerequisite for acceptance, just as modern software development relies on automated testing alongside human code review.

For the AI safety community, the findings raise questions about capability evaluation and containment. A model that can break cryptographic primitives has obvious dual-use implications. The fact that Mythos found these weaknesses with relatively modest compute budgets and non-expert human supervision suggests that the barrier to entry for AI-assisted cryptanalysis is lower than many assumed.

The cost dynamics are particularly noteworthy. For $200,000 in compute costs and a few hundred hours of human validation time, a single research group achieved cryptanalytic breakthroughs that would typically require a multi-institution collaboration over multiple years. As compute costs continue to decline and model capabilities continue to improve, this asymmetry will only grow more pronounced.

What remains unclear is whether the cryptographic community can adapt quickly enough. Standards processes move slowly by design, favoring caution and exhaustive review. AI capabilities are advancing on an exponential trajectory. The tension between these two tempos will shape the security landscape for years to come, and the Mythos Preview findings are an early signal of the challenges ahead.

Share This Article