Get the app
Research

Claude Mythos halved a post-quantum signature's key strength

Anthropic's Mythos model cut the cost of attacking HAWK from 2^64 to 2^38 in 60 hours — after two years of expert review missed it.

Claude Mythos halved a post-quantum signature's key strength

HAWK is a lattice-based digital signature scheme sitting in NIST's third round of post-quantum candidates. Two years of expert review found nothing wrong with it. Claude Mythos Preview found hidden structure in its math in roughly 60 hours, dropping the cost of attacking HAWK-256 from 2^64 steps to 2^38 — about 67 million times less work, and effectively half the advertised key strength.

The second result is arguably weirder. Running autonomously for three days and burning close to a billion tokens, Mythos improved the best known attack on 7-round AES by 200–800×, via a new technique Anthropic calls the Möbius Bridge fingerprinting algorithm. Human researchers then needed about a month just to verify the proof held. Each breakthrough cost roughly $100,000 in API compute — cheap, for original cryptanalysis.

Anthropic is blunt that nothing you use is broken: HAWK was never deployed, full AES-128 has 10 rounds and stands, and "no production software will have to change." Mythos also surfaced a practical attack on 13-round LEA plus early improvements against Serpent, Salsa20, Poseidon and SHA-1.

Why it matters: cryptanalysis was the last field where "experts stared at it for years" counted as a security guarantee — and that guarantee just got repriced at $100k a run.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play