Anthropic's Claude Mythos Preview has delivered what may be one of the most consequential cryptanalysis results in recent memory, discovering fundamental mathematical flaws in HAWKβa post-quantum signature schemeβand identifying weaknesses in a reduced-round variant of AES. The AI model accomplished this feat in just 60 hours of continuous operation at an estimated compute cost of roughly $100,000, according to research documentation published on DEV.to. HAWK (Hash-based Authenticated Key Exchange) is one of several post-quantum cryptographic schemes submitted for NIST standardization as part of the ongoing effort to future-proof encryption against quantum computing threats. The discovery of attackable vulnerabilities in HAWK adds a significant complication to an already complex landscape of post-quantum candidates, suggesting that even schemes considered mathematically promising require extensive scrutiny before deployment in critical infrastructure. The research team leveraged Claude Mythos not just for vulnerability detection but also generated CryptanalysisBench, a new benchmark designed to evaluate AI systems' capabilities in formal cryptanalysis tasks. This tooling represents a potential shift in how cryptographic standards bodies might eventually assess the security of emerging algorithmsβby using AI-assisted analysis to stress-test mathematical assumptions at scale. The AES findings focus on reduced-round variants of the ubiquitous block cipher that underpins most modern encrypted communications. While full-round AES remains computationally unbroken, attacks against weakened versions can provide cryptanalysts with insights into potential structural weaknesses and help predict how more sophisticated attacks might eventually be constructed against stronger configurations.
Implications for Post-Quantum Migration
Industry observers note this development arrives at an awkward moment for organizations already navigating the complexities of post-quantum migration planning. Many enterprises have begun inventorying cryptographic dependencies and selecting algorithms for near-term implementation, only to face continued uncertainty about which schemes will ultimately prove secure. The HAWK vulnerability adds another variable to consider in long-term security architecture decisions. The findings also raise questions about NIST's evaluation processes. While the standardization body conducts extensive mathematical analysis of submitted schemes, the speed at which Claude Mythos identified exploitable flaws suggests that existing review pipelines may need to incorporate AI-assisted cryptanalysis as a standard step. Whether NIST will formally adopt such approaches remains an open question, but the research demonstrates the feasibility of using frontier models to complement human expert review.
Key Takeaways
- Anthropic's Claude Mythos found exploitable flaws in HAWK post-quantum signature scheme and reduced-round AES
- Attack required 60 hours of continuous AI operation at approximately $100K compute cost
- CryptanalysisBench benchmark was produced as a byproduct of the research effort
- Results raise questions about the rigor of existing post-quantum cryptographic evaluations
The Bottom Line
This isn't just an academic exerciseβit's proof that frontier AI models are becoming legitimate tools in the cryptanalyst's arsenal. If $100K and 60 hours can surface real vulnerabilities in schemes being considered for global infrastructure, standards bodies need to factor AI-assisted analysis into their evaluation pipelines immediately. The question is no longer whether AI can break cryptography, but how quickly it will.