Anthropic announced that its AI system, dubbed Mythos, has identified a novel meet-in-the-middle (MITM) attack on a three‑round variant of the Advanced Encryption Standard (AES). By employing a sophisticated fingerprinting method called a Möbius Bridge, the algorithm reduced the required input space to just 289 candidates, a dramatic drop from the thousands traditionally needed.

The reduction translates to a potential speed‑up of 200‑ to 800‑times for the specific attack, according to Anthropic researchers. The claim rests on a laboratory‑scale test using a weakened AES implementation that runs only seven rounds, far fewer than the ten, twelve, or fourteen rounds used in standard AES keys.

"The ability to produce that many inputs makes the attack beyond reach outside of the laboratory," the team wrote. "Further, the actual speed‑up is unknown, since the weakened AES algorithm tested used only 7 rounds." They acknowledge that the findings may not directly apply to full‑strength AES, which remains considerably more resilient.

Anthropic’s blog post frames the discovery as a proof of concept for AI‑assisted cryptanalysis. The company warns that language models are beginning to outpace traditional human‑driven vulnerability research, creating a bottleneck in verification and remediation processes. "The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes struggle to keep up," the post states.

Anthropic's cautions and limits

While the results are striking, Anthropic underscores several caveats. The MITM technique was demonstrated on an algorithm still in its infancy, and there is no evidence yet that the same approach would succeed against widely deployed cryptosystems such as elliptic‑curve cryptography or RSA. Moreover, the study does not reveal whether conventional cryptanalysis methods were already nearing the same breakthrough.

"We predict that the same will soon be true in academic cryptography research," the company added, suggesting that AI‑generated research outputs may soon outstrip the capacity of human experts to validate them. The narrative stops short of claiming an imminent threat to operational encryption, but it signals a shift in how cryptographic weaknesses might be uncovered in the future.

Experts not involved in the study note that while AI tools can accelerate certain phases of cryptanalysis, the underlying mathematics of strong ciphers like full‑scale AES still present formidable hurdles. Nonetheless, the Mythos demonstration adds to a growing body of evidence that large language models can contribute meaningful insights to security research.

Anthropic has not disclosed whether Mythos was applied to other cryptographic targets. The company’s emphasis remains on the methodological advance rather than on immediate practical implications. As AI continues to mature, the balance between automated discovery and human verification will likely become a central theme in the cybersecurity field.

Dieser Artikel wurde mit Unterstützung von KI verfasst.
News Factory APP - agentische News für besseres SEO & AEO.