SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Anthropic's Claude Mythos roughly halves the security of post-quantum signature candidate HAWK
Anthropic's unreleased Claude Mythos model found a key-recovery attack that roughly halves the security of HAWK, a proposed post-quantum signature scheme. Its companion AES result trims an old attack on a weakened cipher and leaves deployed AES as it was.
The Watch · Security desk

What happened
- HAWK had progressed some way through evaluation for a future standard, though no one has deployed or adopted it.
- Mythos produced working code that recovers keys in a few hours against a weakened challenge instance supplied by HAWK's authors, not against the proposed deployment parameters.
- The attack does not carry over to Falcon, the related signature scheme now being standardized, because Falcon rests on a different hard problem.
- The AES attack needs 2^89 cipher operations, and only after the victim has encrypted 2^105 attacker-chosen plaintexts under its secret key.
Why it matters
- decision Anyone weighing HAWK for future use is now looking at a scheme whose available fix, doubling key sizes, gives up the efficiency advantage it was proposed for.
- exposure Migration plans built on standardized post-quantum schemes need no change from this result, because the weakness sits in a candidate nobody has deployed.
- cost The AES result costs operators nothing: no deployed key size or cipher choice needs revisiting on its account.
HAWK is not deployed anywhere, according to a post on the Cryptography Engineering blog [3]. That leaves no production system for an attacker to aim this at. The attack also remains exponential time [6]. Doubling key sizes could in theory win back the lost bits, the blog's author wrote, but HAWK is motivated entirely by being more efficient than the alternatives, and bigger keys make it less efficient [7]. He wrote that this "makes the existence of the scheme much harder to justify" [7].
In our view, how the result was found matters more to post-quantum planners than the result itself. The attack invents no new mathematics. It extends tools that were already well known [9]. Asked about it by the blog's author, Claude said "none of the ingredients are exotic" [10]. He wrote that "someone just did a much more thorough job applying all of our known tools," and that "This is the sort of things that attack AIs excel at." [11] We'd expect other candidates still in evaluation, whose parameters can still change, to get the same exhaustive pass, though a single result against a single scheme does not yet make a pattern.
The AES result is a different class of finding. AES has been a standard since 2001, and the post notes that the deployed version has held up against everything significant thrown at it, including non-public testing by the NSA [12]. Full AES runs 10, 12 or 14 rounds depending on key size, and the Anthropic attack targets a 7-round variant [13]. That is three rounds short of the smallest full cipher [17]. Attacks on 7-round AES already existed. This one is a modest constant-factor improvement on work from 2013 [14].
Both readings come from one blog post. Its author called them his own thoughts and said other people, including domain experts in the two areas, will probably differ [16]. Anthropic published its own account of the research process behind the results [2]. Mythos itself remains unreleased [1].
What to watch
- Whether HAWK's designers answer with larger parameters or the scheme drops out of standards evaluation.
- Whether outside cryptanalysts reproduce the key recovery against the challenge instance or push it toward the proposed deployment parameters.
- Whether Anthropic releases Mythos, letting other researchers run it against other post-quantum candidates.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, its still-unreleased advanced model. One attacks the signature scheme HAWK; the other is an improved attack against reduced-round AES.
- [2]
Anthropic also released a blog post describing the research process that produced these results.
- [3]
HAWK is a proposed post-quantum-safe signature scheme based on the module Lattice Isomorphism Problem (module-LIP). It is not a deployed or standards-adopted algorithm.
- [4]
HAWK is related to the Falcon signature scheme, which is being standardized, but the attack does not transfer to Falcon, which is based on a different hard problem.
- [5]
HAWK was somewhat far along in the process of being evaluated for a future standard.
- [6]
The new key-recovery attack on HAWK is still exponential time but roughly halves the number of bits of security in the algorithm.
- [7]
The weakness could theoretically be fixed by doubling key sizes, but that makes the scheme less efficient; since HAWK is entirely motivated by being more efficient than alternatives, the blog's author wrote that this "makes the existence of the scheme much harder to justify."
- [8]
The attack produced real code that runs in a few hours of wall-clock time against a weakened challenge instance of HAWK that the HAWK authors provided; the instance does not use the parameters proposed for real deployment.
- [9]
The attack does not invent fundamentally new mathematics; it extends tools that were already well known.
- [10]
"none of the ingredients are exotic"
- [11]
"someone just did a much more thorough job applying all of our known tools" ... "This is the sort of things that attack AIs excel at."
- [12]
AES has been a standard since 2001, and the deployed version has withstood everything significant thrown at it, including a substantial amount of non-public testing performed by the NSA.
- [13]
The full AES cipher runs for 10, 12 or 14 rounds depending on key size; the new Anthropic result attacks a weaker 7-round variant.
- [14]
Attacks against 7-round AES are not new; the Anthropic result is a modest constant-factor improvement on previous work from 2013.
- [15]
The new AES attack requires 2^89 cipher operations and is only possible after a real encryptor has produced 2^105 encryptions of chosen plaintexts under their secret key (exponents rendered as '289' and '2105' in the source text); the author wrote that neither is remotely practical.
- [16]
The blog post's author described the analysis as only his thoughts and said other people, including domain experts in the two areas, will probably differ.
- [17]
The 7-round variant attacked is three rounds short of the smallest full AES configuration.
Sources
1 independent publisher whose own reporting we read for this story.
- his July post
blog.cryptographyengineering.com
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Lattice-based cryptographyFollow
- AI-assisted cryptanalysisFollow
- Post-Quantum CryptographyFollow