On July 28, Anthropic disclosed that Claude Mythos Preview, an unreleased frontier model, had developed an improved key-recovery attack against the post-quantum signature candidate HAWK and a faster attack against a reduced version of AES-128. HAWK’s authors later validated the HAWK result, while cryptographers reviewed the AES work, according to Anthropic’s primary report and independent reporting.
The capability test comprised two researcher-selected cryptanalysis projects. The supplied record contains no standardized benchmark score. HAWK is a digital-signature scheme under consideration in the National Institute of Standards and Technology’s Additional Digital Signatures process. AES-128 is the widely deployed symmetric cipher used to encrypt data. Claude attacked seven AES rounds, while production AES-128 uses ten.
HAWK remains a predeployment candidate, and the AES method requires more than 400 octillion chosen messages while leaving the full ten-round cipher outside its reach. CyberScoop describes both results as theoretical and says the AES attack cannot touch the complete version protecting everyday software. The disclosed AES result does not support emergency rotation of production AES-128. It does justify closer review of candidate algorithms and AI-assisted cryptanalysis workflows.
Claude’s route into HAWK
HAWK is a third-round candidate in NIST’s search for additional post-quantum digital-signature standards. Its security rests on the difficulty of a mathematical problem called the Lattice Isomorphism Problem. Anthropic says Claude found a previously unexploited symmetry, known as a nontrivial automorphism, in the lattice HAWK uses.
That symmetry produced an implementable, end-to-end key-recovery attack. According to Anthropic, finding, developing and verifying the method took about 60 hours and approximately $100,000 in API costs. HAWK’s authors validated the result.
The consequence lands inside the standards process. CyberScoop reports that the weakness cuts HAWK’s effective key strength in half, requiring roughly double-sized keys to restore the submitted security level. Anthropic says that increase would erase much of HAWK’s appeal. A candidate built partly around compact keys becomes a different product once its parameter sizes double.
This is standards review working before deployment. NIST has an attack, the scheme’s authors have confirmed it, and implementers can reconsider HAWK before applications accumulate migration costs.
The AES experiment
The AES project used a different setup. An Anthropic researcher built a scaffold that let Claude propose hypotheses, run experiments, reject failed ideas and continue searching. Claude was then asked to improve the best known cryptanalysis of AES.
Within about a week, Anthropic says, Mythos autonomously developed a new attack against seven-round AES-128. By eliminating one guess required by previous methods, the result improved the speed of the best prior attacks on that reduced-round target by a factor of 200–800. Two Anthropic researchers then spent nearly a month gaining confidence in the result.
The data requirement keeps the attack far from operational use. Its chosen-plaintext model gives the attacker access to encryptions of messages selected by the attacker, and the method needs more than 400 octillion such messages, according to CyberScoop. It also stops three rounds short of complete AES-128.
A 200–800-fold research improvement can coexist with an impractical attack. Cryptanalysis measures progress against previous methods, sometimes across deliberately weakened versions of a cipher. Reduced-round attacks help researchers understand safety margins. They do not inherit the security impact of an attack against the deployed cipher.
What the independent reporting confirms
Claims about Claude’s autonomy, internal scaffolding and API costs originate with Anthropic. The external reporting adds scrutiny around the results and their limits.
The New York Times reports that human researchers spent nearly a month checking the AES work. Anthropic told the paper that HAWK’s authors had validated that attack and independent cryptographers had reviewed the AES method. CyberScoop independently reports the predeployment status of HAWK, the seven-round limit, the 200–800-fold improvement and the requirement for more than 400 octillion chosen messages.
Independent review and end-to-end reproduction provide different grades of evidence. The supplied reporting establishes author validation for HAWK and expert review for AES. It leaves open whether outside teams have reproduced the complete AES result from scratch, tested it under separate implementations or extended it beyond Anthropic’s chosen setup.
Human verification also took longer than AI discovery in the AES project. Organizations using AI for cryptanalysis need enough specialist capacity to verify machine-generated attacks, proofs and experimental code. Otherwise, unverified results may accumulate faster than researchers can assess them.
The operator response
Keep production AES unchanged and inventory the exact algorithm variants and parameter sets in use.
A cryptographic inventory should identify the exact algorithm, variant, parameter set and operational role behind every dependency. “AES” is too coarse. “AES-128, ten rounds, deployed for data encryption” separates a production system from the seven-round research target. “HAWK, submitted parameters, experimental signature candidate” separates evaluation work from an approved standard.
Four actions follow:
- Classify deployed, standardized, candidate and experimental algorithms separately. The HAWK result belongs in procurement and architecture reviews even though it creates no installed-base emergency.
- Record parameter choices and upgrade paths. HAWK’s submitted key sizes are central to the new finding. An inventory that records only an algorithm name will miss the operational consequence of altered parameters.
- Shorten review cycles for candidate cryptography. A model completed the HAWK process in roughly 60 hours at an estimated $100,000 in API costs. Security committees should expect faster arrival of credible attacks and reserve cryptographer time before a finding appears.
- Require human validation and outside reproduction before production changes. Anthropic’s AES discovery took about a week, followed by nearly a month of checking. The verification workload belongs in the project budget from day one.
An urgent AES migration would be unsupported because the result applies to seven rounds and an impractical chosen-plaintext setting. The reported 200–800-fold improvement on a heavily studied reduced-round target still warrants incorporation into research review programs. Anthropic supplied the model, scaffolding, cost estimate and initial verification, while outside reproduction remains the next evidence threshold.
HAWK affects standards review while AES shows capability
The HAWK attack can affect a live standards decision. Its discovery arrived while NIST still has room to reject the candidate, revise parameters or request further analysis. Defensive value appears before deployment, exactly where cryptanalysis is cheapest to act upon.
The AES result gives the clearer view of Claude Mythos Preview. The model worked inside a scaffold that generated hypotheses, ran experiments and iterated toward an original algorithmic attack. Software security models have already found implementation defects. This project moved into the mathematics beneath an established cipher.
That distinction deserves precision. Anthropic selected the targets, a researcher built the AES scaffold, substantial compute was available, and human cryptographers spent weeks checking the output. The demonstrated autonomy belongs inside that envelope. The supplied evidence covers neither autonomous target selection nor exploitation of live systems, broad replication across cryptographic families, recursive self-improvement or an attack on full AES-128.
As of July 29, NIST had not announced its next disposition of HAWK, and no supplied source established an outside end-to-end reproduction of Anthropic’s AES method.
The Signal is the public edge of a private practice. Sherpa points the same intelligence engine at one owner's business — competitors, suppliers, regulators, watched daily, graded and sourced. Work with a Sherpa →
