Anthropic says Claude Mythos Preview was able to break a weaker version of AES and orchestrated another improved attack against the cryptographic system HAWK
Claude Mythos Preview discovered new attacks in testing against weakened cryptographic algorithms, which protect online financial transactions …
New York TimesDustin Volz
Context & Ripple Effects
Anthropic had already positioned Mythos Preview as a high-end cyber-capable system after reporting thousands of severe vulnerabilities, including findings across major operating systems and browsers its earlier vulnerability-discovery results. Independent analysis also reported strong performance on expert capture-the-flag tasks expert-level security challenges.
The cryptography tests extend that arc from software flaws to attack construction against cryptographic designs. Anthropic has said it would limit Mythos Preview access to organizations maintaining critical software a restricted critical-software rollout, making the reported capability relevant both to defensive testing and to access controls.
First-order effects
Maintainers and users of HAWK can scrutinize the improved attack path Anthropic reports; the weakened-AES result is a test finding, not evidence that standard AES has been broken.
Anthropic gains a concrete cryptanalysis benchmark for Mythos Preview, reinforcing the distinction it has drawn between this system and its less cyber-capable public models.
Second-order effects
Organizations evaluating AI-assisted security tooling will have stronger reason to include cryptographic review—not only vulnerability scanning—in controlled model assessments.
Cryptographic-system developers may face added pressure to validate designs against agentic, iterative attack workflows, while model providers will need to show that access restrictions match those capabilities.
Third-order effects
If repeated across models, AI-assisted cryptanalysis could compress the time between a proposed cryptographic design and meaningful adversarial review, raising the value of early, independent evaluation.
The case strengthens the dual-use governance question: the same systems that help defenders test critical software can also lower the expertise required to develop attacks, favoring tiered access and auditability over broad release.
The trend: Frontier AI is moving from identifying software weaknesses toward autonomously assembling more sophisticated security and cryptographic attacks, intensifying the need for controlled defensive deployment.
New Anthropic research: Discovering cryptographic weaknesses with Claude. Claude Mythos Preview has helped our researchers find weaknesses in cryptographic algorithms—the mathematical methods that are used to keep data private. Read more: https://anthropic.com/...
crypto research is so funny man to be clear the AES attack here is a real improvement of SOTA and impressive for claude to find on its own but also lol at shortening aes128 to 7 rounds and needing 2^105 known plaintexts
“Mythos Preview found a previously-unknown attack that reduced the scheme's key strength by half” And this happened, with no quantum computer involved yet.
oh my god. the fundamental principles upon which almost all of cyber security, hell even some physical security itself is built are rapidly breaking down. if this is true, & a model was able to find a way to break symmetric cryptography every piece of infrastructure is basically …
The symmetric cipher is a reduced version of the Advanced Encryption Standard (AES)—which has received decades of scrutiny (more than almost any other encryption algorithm). In a week, Mythos Preview found a way to speed up an attack on this version of AES by 200-800×.
Mythos Preview did most of this work autonomously, with occasional human guidance. Each of the two results cost roughly $100,000 in API usage. We disclosed the findings in advance to the algorithms' authors, as well as to US government and industry partners.
Still, both results show that frontier AI models are capable of doing expert-level cryptography research. This has important defensive applications—testing the algorithms that keep our online activity secure, and ultimately helping to make digital systems safer.
The digital signature scheme is HAWK, which is designed to be robust even against hypothetical quantum computers. HAWK has survived two years of expert review, but in 60 hours Mythos Preview found a previously-unknown attack that reduced the scheme's key strength by half.
By running models *slightly* longer than in our recent benchmark evaluation (one billion tokens and >$100k ) Mythos found some impressive attacks on cryptographic schemes
These are substantial research advances, but they don't have a practical impact on today's systems. HAWK is a proposed scheme that hasn't been deployed anywhere, and the AES attack we discovered was on a weaker version and does not break the full cipher.
Claude discovered weaknesses in a highly-secure digital signature scheme (used to verify identity digitally) and a well-known symmetric cipher (used to encrypt data).
AI is accelerating all the work that requires deep analysis and analytical thinking. In most cases it outperforms the human brain and breaks previously made assumptions. …
Claude Mythos Preview just found a mathematical flaw in a NIST post-quantum signature candidate. Not a bad implementation. A weakness in the algorithm itself. …
Anthropic says Mythos figured out how to weaken a post-quantum cryptography algorithm being considered for standardization and break a weakened version of the widely used AES standard. www.anthropic.com/research/dis... [image]
this will take a while to diffuse, but the idea that LLM results derive primarily from the expertise of the operator is fully dead — www.anthropic.com/research/dis... [embedded post]
This is a very cool and exciting discovery by Claude Mythos! — It found a serious 𝒎𝒂𝒕𝒉𝒆𝒎𝒂𝒕𝒊𝒄𝒂𝒍 attack on the post-quantum signature scheme HAWK, an “on-ramp” candidate for potential NIST standardization. …
Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private).