Anthropic Claude AI Discovers Cryptographic Weaknesses in HAWK and AES Research
Anthropic researchers have announced a major advancement in AI-assisted cryptanalysis after its experimental Claude Mythos Preview model autonomously identified significant mathematical weaknesses in two prominent cryptographic systems.
The discoveries, which emerged through largely autonomous AI workflows with minimal human intervention, highlight the growing capability of artificial intelligence to assist in advanced cybersecurity research.
While neither finding presents an immediate threat to production environments, the research demonstrates how AI may soon play a central role in discovering vulnerabilities that traditional expert analysis could overlook.
Anthropic Claude AI Discovers Cryptographic Weaknesses
The most significant discovery targeted HAWK, a post-quantum digital signature algorithm currently undergoing evaluation in the National Institute of Standards and Technology (NIST) Post-Quantum Cryptography standardization process.
HAWK has successfully progressed through multiple rounds of expert cryptographic review over the past two years. Despite extensive scrutiny by leading researchers, Claude Mythos identified a previously unknown nontrivial automorphism within the lattice structure that underpins the cryptographic scheme.
This mathematical property effectively reduced the algorithm’s security strength by approximately half, lowering the estimated computational complexity required for an attack on HAWK-256 from 2⁶⁴ operations to approximately 2³⁸ operations.
Although HAWK has not yet been standardized or deployed in production systems, the finding underscores the importance of continuous cryptographic evaluation before widespread adoption.
Anthropic’s second major breakthrough focused on a reduced version of the Advanced Encryption Standard (AES-128), one of the world’s most widely deployed symmetric encryption algorithms.
Claude Mythos independently developed a new analytical technique called the Möbius Bridge, which improves existing meet-in-the-middle cryptanalytic attacks against a deliberately weakened seven-round implementation of AES-128.
The technique removes one exhaustive key-guessing stage from previous attacks, accelerating theoretical attack performance by approximately 200 to 800 times.
Researchers emphasized that this result affects only the reduced-round research variant requiring approximately 2¹⁰⁵ chosen plaintexts and does not impact the full ten-round AES-128 implementation used to protect government, enterprise, financial, and consumer systems worldwide.
According to Anthropic, both discoveries emerged through highly autonomous AI-driven research workflows. The HAWK investigation required roughly 60 hours of semi-autonomous computation, with human researchers primarily acting as project coordinators rather than providing direct cryptographic guidance.
Interestingly, two independent AI worker agents collaborated throughout the process. One agent initially rejected the proposed attack path as mathematically infeasible before another independently refined the approach and successfully demonstrated the complete exploit.
This collaborative reasoning between AI agents provided researchers with valuable insights into how multiple autonomous systems may solve complex scientific problems more effectively than individual models working alone.
The AES research followed an even more unusual development path. Initially, Claude Mythos refused to investigate the cipher, reasoning that AES had undergone decades of intensive academic scrutiny and that discovering meaningful improvements would be unlikely.
Researchers then encouraged the model through informal prompts, urging it to search for unconventional mathematical approaches instead of relying on existing techniques.
Over approximately three days and nearly one billion generated output tokens, the AI autonomously rewrote portions of its own experimental evaluation framework before ultimately developing the Möbius Bridge cryptanalytic method.
Anthropic estimated that each of the two primary research efforts consumed approximately $100,000 in API compute resources, reflecting the computational intensity required for advanced AI-assisted mathematical discovery.
Beyond these headline results, Anthropic reported several additional cryptographic improvements involving widely studied algorithms.
The AI demonstrated a practical attack against 13-round LEA, a lightweight encryption algorithm standardized for international applications, while also identifying incremental improvements against Serpent-128, Salsa20, Poseidon, and SHA-1.
Although none of these findings create immediate security risks for operational systems, they illustrate that AI models are steadily expanding their ability to contribute to sophisticated cryptanalysis across diverse cryptographic families.
To support future research, Anthropic partnered with ETH Zurich, Tel Aviv University, and the University of Haifa to introduce CryptanalysisBench, a new benchmark designed to evaluate how effectively large language models perform against modern cryptographic challenges.
Throughout the project, Anthropic followed responsible disclosure practices by privately notifying HAWK’s developers and coordinating with government agencies and industry stakeholders before publicly releasing its findings.
Anthropic emphasized that these discoveries validate the value of adversarial cryptographic review rather than signaling an immediate crisis.
However, the company cautioned that as AI systems become increasingly capable of performing autonomous mathematical reasoning, the cybersecurity community must prepare for a future where AI identifies vulnerabilities in production cryptographic systems faster than human experts can independently verify, assess, and remediate them.
The research represents an important milestone in AI-assisted cybersecurity, demonstrating that artificial intelligence is rapidly evolving from a tool for software analysis into a powerful collaborator in fundamental cryptographic research.
No Comment! Be the first one.