Anthropic’s Claude Mythos Uncovers Vulnerabilities in Encryption Algorithms

0
3

Key Takeaways

  • Anthropic’s Claude Mythos Preview uncovered a mathematical shortcut in the HAWK post‑quantum signature scheme that halves its effective key strength.
  • The same AI model devised a “Möbius Bridge” shortcut that makes the strongest known theoretical attack on a seven‑round AES variant 200–800× faster, though the attack remains infeasible against full‑strength AES.
  • Both discoveries were disclosed responsibly: HAWK’s designers were notified in June, findings were coordinated with NIST, and government/industry partners were briefed before public release.
  • Researchers collaborated with ETH Zurich, Tel Aviv University, and the University of Haifa to create CryptanalysisBench, a shared tool for measuring AI‑driven cryptanalytic performance across ciphers.
  • While the revealed weaknesses do not affect software currently in use, they underscore the importance of ongoing cryptographic visibility, PQC readiness, and treating trust infrastructure as an operational, continuously monitored asset.
  • Anthropic highlights an open question: how the community should respond if an AI model ever finds a vulnerability in a cryptosystem that protects critical infrastructure with immediate real‑world impact.

Introduction and Overview of Anthropic’s Research
Anthropic announced on Tuesday that its frontier AI model, Claude Mythos Preview, helped researchers identify new weaknesses in two cryptographic constructions. In a detailed blog post, the company described the findings as a “substantial” research advancement but stressed that neither flaw impacts any software presently deployed. The attacks described represent the strongest known theoretical breaks to date, yet they remain confined to academic or simplified settings. By publishing the work, Anthropic aims to stimulate discussion about the responsibilities that arise when powerful language models uncover cryptographic vulnerabilities.


Weakness in HAWK Digital Signature Scheme
One of the vulnerabilities lies in HAWK, a lattice‑based digital signature scheme currently under review by the National Institute of Standards and Technology (NIST) for post‑quantum cryptography (PQC). Working alongside a human cryptographer, Mythos uncovered a mathematical shortcut known as a nontrivial automorphism embedded in the lattice structure that underpins HAWK’s security. This shortcut effectively reduces HAWK’s key strength by half, meaning that to retain the same security level, key sizes would need to be doubled. Anthropic noted that such a requirement would erase many of the performance and size advantages that made HAWK an attractive PQC candidate in the first place.


Implications for HAWK and the NIST PQC Process
Ellen Boehm, senior vice president of strategy and AI innovation at Keyfactor, praised the discovery as evidence that the NIST PQC evaluation process is functioning as intended. She emphasized that the finding elevates the need for organizations to maintain clear visibility of where cryptography resides within their enterprise, understand the business systems and processes it supports, and develop concrete PQC readiness plans—even if they have not yet done so. Boehm warned against treating cryptographic infrastructure as a static element that only changes when new algorithms are standardized; instead, it must be managed continuously.


Weakness Found in Simplified AES (Seven‑Round Variant)
The second weakness concerns a reduced‑round version of the Advanced Encryption Standard (AES), the symmetric cipher NIST adopted in 2001 and the backbone of everyday data‑in‑transit protection. While real‑world AES employs ten sequential encryption rounds, researchers often analyze a seven‑round test variant to gauge security margins. Working largely autonomously, Mythos invented a mathematical shortcut dubbed the “Möbius Bridge.” This shortcut eliminates the need to check 256 separate values against a memory table—a step required in prior theoretical attacks on the seven‑round version. Combined with other optimizations, the Möbius Bridge makes the strongest known theoretical attack on seven‑round AES 200 to 800 times faster.

Nevertheless, the attack remains purely theoretical: it would require an impossible quantity of target data—over 400 octillion encrypted messages—and cannot touch the full 10‑round AES that safeguards current software. Anthropic reiterated that real‑world systems remain completely safe from this particular line of attack.


Disclosure Practices and Collaborative Tool Development
Anthropic followed standard responsible‑disclosure procedures. The HAWK designers were notified in June, and the public release was coordinated via a NIST mailing list after briefings with government and industry partners. To facilitate further research, the company teamed with scholars from ETH Zurich, Tel Aviv University, and the University of Haifa to build CryptanalysisBench, a shared testing platform that enables other investigators to measure how AI systems perform against a variety of ciphers. This collaborative tool aims to standardize evaluations and accelerate progress in AI‑assisted cryptanalysis.


Broader Context: AI in Cryptanalysis and the Cybersecurity Threat Landscape
The findings arrive amid growing deployment of frontier AI models by cybersecurity professionals seeking vulnerabilities across software stacks. In June, the Five Eyes intelligence alliance warned that advanced AI capable of wreaking havoc in the cyber domain could be operational within months. Yet, a recent report observed that despite a surge in uncovered bugs, the overall threat level across the internet has not shifted materially. Anthropic anticipates that the same AI capabilities will eventually be turned toward widely deployed cryptographic systems, raising pressing questions about readiness and response.


Open Questions and Future Considerations
Anthropic explicitly flagged an unresolved issue: how researchers, companies, and governments should react if a language model discovers a flaw in a cryptosystem that protects critical infrastructure and enables an immediate real‑world impact. The company calls for proactive consideration of protocols governing disclosure, mitigation, and coordination in such scenarios. Boehm echoed this sentiment, urging enterprises to treat their trust infrastructure as an ongoing, operational concern rather than a static component refreshed only when new algorithms are released. Continuous monitoring, regular risk assessments, and investment in crypto‑agility are presented as essential defenses against future AI‑driven cryptanalytic breakthroughs.


Conclusion and Takeaway for Enterprises
Anthropic’s work illustrates both the promise and the peril of applying sophisticated AI to cryptanalysis. While the uncovered weaknesses in HAWK and a simplified AES variant do not threaten deployed systems today, they serve as a vivid reminder that cryptographic security must be viewed through a lens of perpetual vigilance. Organizations should invest in comprehensive cryptographic inventories, maintain readiness for post‑quantum transitions, and embrace tools like CryptanalysisBench to evaluate emerging threats. By treating cryptographic infrastructure as an active, continuously managed asset—guided by clear disclosure practices and collaborative research—enterprises can better safeguard themselves against the evolving capabilities of AI‑powered attackers.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here