Claude Mythos research examines weaknesses in HAWK and reduced AES

Anthropic’s Frontier Red Team just showed that a frontier model can find mathematical cracks in crypto designs that survived years of human review. Deployed systems are still fine. The research bar just moved.
In a July 28 research post, Anthropic reports that Claude Mythos Preview improved the best-known key-recovery attack on HAWK, a NIST post-quantum signature candidate, and discovered a Mรถbius Bridge technique that speeds meet-in-the-middle attacks on 7-round AES by 200โ800ร. Neither result breaks production cryptography. Both show what happens when an agentic model is pointed at algorithm design, not just buggy implementations.
What Mythos Preview found on HAWK
HAWK is a third-round candidate in NIST’s call for additional digital signatures meant to survive quantum computers. Its security rests on the Lattice Isomorphism Problem. Working with Mythos Preview, an Anthropic researcher developed an attack that finds a previously unexploited nontrivial automorphism in HAWK’s lattice, enabling a faster enumeration attack.
Anthropic’s numbers are concrete. The expected cost of full key recovery against small HAWK-256 was thought to be 2^64; Mythos demonstrated 2^38. In plain terms, the post says the attack roughly halves effective key strength โ you would need to double HAWK key sizes to recover the claimed security level, which undercuts much of what made the scheme attractive. Finding, developing, and verifying the attack took about 60 hours and roughly $100,000 in API cost. The work was semi-autonomous: human input mostly project management, not lattice expertise.
HAWK is a candidate, not a deployed standard. Anthropic shared the attack with HAWK’s authors in June and coordinated public disclosure to the NIST mailing list with the blog release. The attack is specific to HAWK; Anthropic says it does not hit other NIST post-quantum signature candidates or lattice cryptography in general.
The Mรถbius Bridge angle on reduced-round AES
AES-128 uses 10 rounds. Academics study weaker round-reduced variants to probe attack techniques. Mythos improved the strongest known meet-in-the-middle line on 7-round AES under a chosen-plaintext model that already assumes an impractical 2^105 chosen plaintexts.
The model’s contribution is a fingerprinting method it called a Mรถbius Bridge. Prior work had to enumerate 256 values at one stage; Mythos found a fingerprint invariant to that guess, cutting that work by a factor of 256, then stacked optimizations that yield a 200โ800ร speedup depending on how runtime is measured. Discovery was almost fully autonomous after a researcher built a scaffold โ a few substantive prompts over days, then hundreds of human hours validating claims for the paper.
Still: seven rounds, not ten. Full AES is not broken.
Production crypto is not on fire โ yet
Anthropic is explicit. No production software must change because of these two results. HAWK is not deployed. The AES result does not reach the full cipher.
The sharper point is process. Mythos is doing cryptanalysis at expert research pace: literature review, hypothesis, experiment, verification. Anthropic also reports practical end-to-end key recovery on 13-round LEA (full cipher: 24 rounds) and preliminary work on reduced-round Serpent plus smaller gains elsewhere.
CryptanalysisBench and the next stress test
With partners at ETH Zurich, Tel Aviv University, and TU Berlin, Anthropic released CryptanalysisBench so others can measure LLM cryptanalysis without reinventing the harness. Full papers on HAWK, AES (plus chain-of-thought for the key insight), and the benchmark are linked from the research post.
Analysis: this is cryptography working as designed โ adversarial review before deployment โ with a new reviewer that does not sleep. The open question is governance when a model finds a flaw that does hit live systems. Anthropic says it briefed U.S. government and industry partners in advance. That conversation needs to outrun the next capability jump. HAWK’s key-size math just got harder. Your TLS stack is fine today.



