Claude Mythos Weakens HAWK and Speeds Up a Seven-Round AES Attack
Anthropic published research on July 28 reporting that Claude Mythos Preview helped derive a practical key-recovery attack against the HAWK-256 test parameter and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK team confirmed the result and withdrew its candidate from NIST's process on July 29. Neither finding breaks production AES or a deployed post-quantum standard.
Anthropic published two AI-assisted cryptanalysis results on July 28: a key-recovery attack that substantially weakens the HAWK post-quantum signature candidate and a faster attack on seven-round AES-128. The immediate operational scope is narrow, but the HAWK result produced a concrete standards consequence one day later.
On July 29, the HAWK team said it had confirmed that Anthropic's attack approximately halves the lattice-reduction block size needed to recover an equivalent secret key. The team withdrew HAWK from the National Institute of Standards and Technology's additional digital-signature standardization process, saying straightforward mitigations would make the scheme uncompetitive. NIST updated its candidate page to show the withdrawal.
A practical result against the HAWK test parameter
Anthropic's HAWK paper describes a previously unused automorphism, or symmetry, in the lattice underlying the signature scheme. The method constructs a public lattice, reduces the key-recovery problem to finding a short vector in roughly half the prior dimension, and reconstructs functionally equivalent signing material.
The released implementation recovers a HAWK-256 secret key end to end within a few hours on a single 96-core server and verifies the result with the HAWK reference implementation. HAWK-256 is a cryptanalytic test parameter, not one of the larger security-level parameter sets. The paper estimates lower attack costs for HAWK-512 and HAWK-1024, but both remain impractical to attack with the published method.
The HAWK team's independent confirmation and withdrawal are more consequential than the challenge-parameter demonstration alone. They show that the result changed the scheme's viability inside an active standards process, while not implying that deployed post-quantum systems were compromised.
Faster reduced-round AES, not a break of AES-128
The second paper targets seven of AES-128's ten rounds. It removes one guessed key byte from a prior meet-in-the-middle attack through an invariant fingerprint called a Möbius Bridge. Depending on how runtime is counted, Anthropic reports a 200- to 800-fold improvement.
The attack still assumes roughly 2^105 chosen plaintexts and requires infeasible time and memory. The researchers validated components and smaller-scale experiments rather than executing a complete full-cost recovery against seven-round AES-128. Standard ten-round AES-128 remains outside the result, and Anthropic said no production software needs to change.
AI accelerated discovery; verification remained decisive
Anthropic says Mythos Preview produced much of the mathematical work while human researchers supplied direction, compute, and extensive checking. The release includes two technical papers and reproducibility artifacts. The public record also contains confirmation from the HAWK team and NIST's updated status page.
For security and ML practitioners, that sequence is the important one: model-generated hypotheses became actionable only after implementation checks, expert review, public artifacts, and standards-community scrutiny. AI can widen the cryptanalytic search space, but claims this consequential still require evidence that other researchers and institutions can inspect.
Key Points
- 1The HAWK team confirmed Anthropic's attack and withdrew HAWK from NIST's additional-signature process on July 29.
- 2The practical recovery targets HAWK-256, while the larger parameter sets remain impractical to attack despite lower estimated security.
- 3The AES result applies to seven rounds and remains infeasible; standard ten-round AES-128 is not broken.
Scoring Rationale
The research directly caused a post-quantum signature candidate to be withdrawn from an active NIST process, while the AES result remains a narrower reduced-round advance without production impact.
Sources
Primary source and supporting public references used for this report.
Practice with real FinTech & Trading data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all FinTech & Trading problems
