Anthropic's Claude Mythos found a bug NIST's HAWK wish it hadn't 🔐
Anthropic said Monday that an unreleased version of its most powerful AI model discovered two previously unknown attacks on cryptographic algorithms, one of them against a scheme currently competing to become a U.S. federal standard. The company published the findings on July 28, 2026 in research titled "Discovering cryptographic weaknesses with Claude," and disclosed both results to the algorithms' authors and to U.S. government and industry partners before publication.
The first attack targets HAWK, a digital signature system built to resist future quantum computers. NIST moved HAWK into the third round of its post-quantum signature competition in May, where it remains the last lattice-based candidate standing. According to Anthropic, Claude identified a symmetry in HAWK's math that no human researcher had previously exploited. For the smallest configuration, the cost of recovering a secret key fell from 2^64 operations to 2^38 — roughly 67 million times less work. The proposed fix roughly doubles HAWK's key sizes. "Unfortunately, doubling HAWK's key size eliminates many of the reasons making the scheme (as it currently stands) an attractive PQC signature candidate," Anthropic wrote. The company coordinated the HAWK disclosure with NIST.
The second attack targets AES, the cipher used to encrypt HTTPS traffic, disk storage and exchange backends. Full AES-128 uses 10 rounds of scrambling; researchers challenged Claude to attack a 7-round research variant that had not been improved upon since 2013. Researchers forbade the model from using the five established families of AES cryptanalysis and asked it to invent a sixth, citing the precedent that the first differential attack "didn't beat anything — it invented the game." The model was also given working notes from prior agent runs that had already tested roughly 200 failed variants. It declined to produce a result. "On AES-128 r5/r6/r7 it found nothing because there's nothing easy to find; this is the most-studied block cipher in existence," Claude told researchers, according to transcripts Anthropic published.
HAWK has not been deployed anywhere, and Bitcoin ($BTC) continues to use ECDSA, the pre-quantum signature scheme that HAWK and similar candidates are intended to eventually replace.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.