Discovering cryptographic weaknesses with Claude

Jul 28, 2026 — Frontier Red Team

Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms. The first attack significantly weakens HAWK, a digital signature scheme built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems.

HAWK attack

HAWK is a third-round candidate in NIST’s Additional Digital Signatures call (post-quantum). Despite surviving two rounds of expert human review over ~two years, Mythos improved the best-known attack in about 60 hours of work — effectively cutting key strength in half (e.g., HAWK-256 expected cost thought ~2^64 demonstrated ~2^38). Attack finds a nontrivial automorphism in the lattice used by HAWK (Lattice Isomorphism Problem). Doubling key sizes would erase much of HAWK’s attractiveness as a PQC candidate. Attack is HAWK-specific; does not impact other NIST PQC candidates or lattice crypto in general. Disclosed to HAWK authors in June; coordinated NIST mailing list disclosure with publication. ~$100,000 API cost.

Reduced-round AES attack

Mythos improved meet-in-the-middle cryptanalysis of 7-round AES-128 (full AES-128 has 10 rounds). Invented a fingerprinting technique dubbed “Möbius Bridge,” removing a factor-of-256 enumeration stage and yielding a 200–800× speedup versus prior best attacks under a chosen-plaintext model with 2^105 plaintexts — still completely impractical and does not break production AES. Discovered almost entirely autonomously via an experimental scaffold; ~one week model work then weeks of human validation. Also ~$100,000 API cost.

Further work and tooling

  • Practical attack on 13-round LEA (full cipher 24 rounds) recovering key in under an hour on a desktop — not applicable to full LEA
  • Attack on 6-round Serpent-128; limited improvements on Salsa20, Poseidon, SHA-1
  • Partnered with ETH Zurich, Tel Aviv University, and TU Berlin on CryptanalysisBench
  • Shared advance copies with US government and industry partners