Anthropic

Claude Mythos Rewrites HAWK Attacks in 60 Hours

Anthropic's Frontier Red Team: Claude Mythos Preview cut HAWK-256 attack cost from 2^64 to 2^38 in 60 hours and sped up 7-round AES-128 attacks 200-800x.

Claude Mythos Rewrites HAWK Attacks in 60 Hours — article cover

On July 28, Anthropic’s Frontier Red Team published “Discovering cryptographic weaknesses with Claude,” a report on letting Claude Mythos Preview run attack research against two well-known cryptographic targets: HAWK, a post-quantum signature scheme, and a round-reduced variant of AES-128. Both targets yielded real progress, making this one of the most concrete demonstrations yet of automated vulnerability research with AI. The framing matters as much as the numbers: this was not a model answering cryptography exam questions, but a model working an open research problem for days and producing a result the field has to take seriously.

HAWK: 60 Hours, From 2^64 to 2^38

HAWK is a candidate in NIST’s additional signatures process, the track that will standardize post-quantum signature schemes beyond the first selections. It descends from the Falcon line of work and aims for signatures compact enough to run on constrained devices — which is exactly the kind of design where implementation subtleties and analysis margins get scrutinized for years before standardization.

According to the report, Claude Mythos Preview improved the best-known key recovery attack against HAWK after 60 hours of work in total: the expected attack cost against HAWK-256 dropped from 2^64 to 2^38 — 26 bits gone. On a logarithmic scale that is the difference between an infeasible computation and a merely enormous one. A record accumulated by human cryptographers over years of public analysis moved in less than three days of model work time.

AES: The Möbius Bridge Fingerprinting Technique

The second result is on the symmetric side. Mythos developed a fingerprinting technique called “Möbius Bridge” that speeds up attacks on 7-round reduced AES-128 by 200 to 800 times. Fingerprinting is a classic idea in symmetric cryptanalysis: mark intermediate states so that partial information can be matched and reused across rounds or encryptions, squeezing signal out of what looks like noise. What is new here is who did the inventing — the technique did not come out of a human researcher’s notebook but out of model-generated analysis that humans then verified. To be clear: this is a research variant with the rounds deliberately cut to seven. Full 10-round AES-128 was not broken, and everyday encrypted traffic is not affected.

A Billion Tokens and a $100,000 Bill

The method details are just as noteworthy. Each of the two main attacks cost roughly $100,000 in API fees. The AES discovery surfaced only after Claude generated about one billion output tokens over several days of largely autonomous work. The workflow was “humans set the goal, the model runs the experiments”: human cryptographers defined the attack surface and the evaluation criteria, while the model handled the mass of trying, verifying, and iterating. The cost came in below what a comparable human team would burn, but it is far from pocket change — and that price point is itself information. Attack research at this level now has a meter running on it, denominated in tokens instead of headcount, and anyone with a budget in the low six figures can commission a serious attempt at an open cryptanalysis problem.

Why Deployed Systems Are Still Safe

The report is explicit that neither result affects deployed systems. HAWK is still in evaluation at NIST and has not seen wide adoption; the AES attack applies only to the 7-round variant. Standards bodies assume attacks only get better over time, and this report is a reminder of how fast “better” can arrive now — a candidate scheme’s safety margin got repriced in a summer, before it ever shipped.

The real signal sits on the capability curve. Given a clear goal and tools, a model can now push research forward in cryptography — a field with almost no tolerance for error, where a wrong claim wastes a reviewer’s month and a right one reshapes a standard. Anthropic and the UK’s AISI previously assessed Mythos Preview’s cybersecurity capabilities; this new report lays the offensive results on the table. For defenders, three things follow. Attack research scales with compute budgets rather than researcher headcount. Safety margins on reduced-round and niche schemes should be treated as shorter than the literature suggests. And red teams using AI to find weaknesses is no longer a thought experiment — the defensive side of the house will have to run the same kind of autonomous analysis just to keep pace.

Sources

  • Anthropic — Discovering cryptographic weaknesses with Claude
  • red.anthropic.com — Assessing Claude Mythos Preview’s cybersecurity capabilities

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL