Anthropic says Claude Mythos Preview was able to break a weaker version of AES and orchestrated another improved attack against the cryptographic system HAWK
Claude Mythos Preview discovered new attacks in testing against weakened cryptographic algorithms, which protect online financial transactions, private communications and more.
New York TimesDustin Volz
Context & Ripple Effects
This extends Anthropic’s earlier account of Mythos Preview finding high-severity flaws across major software platforms, following its reported strong performance on expert security challenges. The new tests move that capability into cryptographic analysis, where even work against weakened algorithms can help benchmark what AI-assisted attack research can do.
Anthropic had already said it would limit Mythos Preview to organizations maintaining critical software through a restricted-access deployment model. That containment posture matters more as the model is reported to coordinate improved attacks against a named cryptographic system.
First-order effects
Anthropic gains a new security-research result for Mythos Preview: it reportedly found attacks against a weakened AES variant and improved an attack on HAWK, rather than merely identifying conventional software bugs.
Maintainers and evaluators of HAWK and related cryptographic implementations have a concrete prompt to scrutinize the reported attack path and its assumptions; the result does not establish that standard AES has been broken.
Second-order effects
Security teams assessing advanced models will need to treat cryptanalysis and attack orchestration as distinct capabilities alongside vulnerability discovery, building on Mythos Preview’s earlier broad vulnerability findings.
Restricted-access providers face greater pressure to show that access controls, trusted-user programs, and safety claims match models’ expanding offensive-security utility.
Third-order effects
If similar results recur, cryptographic review may become an increasingly AI-assisted, continuous process, narrowing the gap between academic attack research and operational security testing.
The episode strengthens the case for governance that differentiates defensive evaluation from scalable offensive deployment, though its significance depends on whether the techniques transfer beyond deliberately weakened or test settings.
The trend: Advanced coding agents are evolving from bug finders into dual-use security researchers that can help generate and refine attacks across more layers of the computing stack.
Still, both results show that frontier AI models are capable of doing expert-level cryptography research. This has important defensive applications—testing the algorithms that keep our online activity secure, and ultimately helping to make digital systems safer.
These are substantial research advances, but they don't have a practical impact on today's systems. HAWK is a proposed scheme that hasn't been deployed anywhere, and the AES attack we discovered was on a weaker version and does not break the full cipher.
Mythos Preview did most of this work autonomously, with occasional human guidance. Each of the two results cost roughly $100,000 in API usage. We disclosed the findings in advance to the algorithms' authors, as well as to US government and industry partners.
The digital signature scheme is HAWK, which is designed to be robust even against hypothetical quantum computers. HAWK has survived two years of expert review, but in 60 hours Mythos Preview found a previously-unknown attack that reduced the scheme's key strength by half.
New Anthropic research: Discovering cryptographic weaknesses with Claude. Claude Mythos Preview has helped our researchers find weaknesses in cryptographic algorithms—the mathematical methods that are used to keep data private. Read more: https://anthropic.com/...
Claude discovered weaknesses in a highly-secure digital signature scheme (used to verify identity digitally) and a well-known symmetric cipher (used to encrypt data).
The symmetric cipher is a reduced version of the Advanced Encryption Standard (AES)—which has received decades of scrutiny (more than almost any other encryption algorithm). In a week, Mythos Preview found a way to speed up an attack on this version of AES by 200-800×.
oh my god. the fundamental principles upon which almost all of cyber security, hell even some physical security itself is built are rapidly breaking down. if this is true, & a model was able to find a way to break symmetric cryptography every piece of infrastructure is basically …
“Mythos Preview found a previously-unknown attack that reduced the scheme's key strength by half” And this happened, with no quantum computer involved yet.
crypto research is so funny man to be clear the AES attack here is a real improvement of SOTA and impressive for claude to find on its own but also lol at shortening aes128 to 7 rounds and needing 2^105 known plaintexts
By running models *slightly* longer than in our recent benchmark evaluation (one billion tokens and >$100k ) Mythos found some impressive attacks on cryptographic schemes
this will take a while to diffuse, but the idea that LLM results derive primarily from the expertise of the operator is fully dead — www.anthropic.com/research/dis... [embedded post]
This is a very cool and exciting discovery by Claude Mythos! — It found a serious 𝒎𝒂𝒕𝒉𝒆𝒎𝒂𝒕𝒊𝒄𝒂𝒍 attack on the post-quantum signature scheme HAWK, an “on-ramp” candidate for potential NIST standardization. …
Anthropic says Mythos figured out how to weaken a post-quantum cryptography algorithm being considered for standardization and break a weakened version of the widely used AES standard. www.anthropic.com/research/dis... [image]
AI is accelerating all the work that requires deep analysis and analytical thinking. In most cases it outperforms the human brain and breaks previously made assumptions. …