When Anthropic dropped cryptanalysis results in late July 2026, the internet did what it always does—immediately picked a side and dug in. One faction saw 'AI breaks AES' and started drafting blog posts about the death of encryption. The other shrugged and called it another marginal academic exercise. Both were wrong, according to Matthew Green at Cryptography Engineering.

What Actually Happened

The technical reality sits somewhere between those extremes. Anthropic's paper represents genuine cryptanalysis work applied to real cryptographic systems—but it's not a break of AES in any practical sense. The panic stems from misreading what the research demonstrates versus what practitioners actually deploy. Green's analysis cuts through the noise by examining the methodology rather than extrapolating headline-ready implications.

Why Verification Matters Now

This episode crystallizes something critical about AI safety research and cryptography: verification is now a full-time job. When major labs publish security-adjacent work, the burden falls on cryptographers like Green to separate signal from noise before the takes calcify into conventional wisdom. The problem isn't that Anthropic published—it's that the ecosystem lacks infrastructure for rapid peer review at scale.

The Real Threat Model

What Green's analysis reveals is that we should be asking different questions about AI and cryptography. Not 'can AI break AES?' but rather: how do LLM-assisted attackers change threat models? What happens when side-channel attacks get automated? The research Anthropic published speaks to these harder questions, even if the headline-grabbing framing obscured that.

Key Takeaways

  • Don't read cryptanalysis papers through a 'break vs no break' lens—threat modeling is more nuanced than that
  • Matthew Green's Cryptography Engineering remains essential reading for calibrated takes on security research
  • The AI safety community needs better channels for publishing technical work without triggering mass misinterpretation

The Bottom Line

Anthropic published legitimate cryptanalysis. The response proved that the infosec community desperately needs more bridges between cutting-edge ML research and traditional cryptography expertise—or we'll keep cycling through panic and dismissal forever.