Anthropic revealed that its Claude Mythos preview has discovered two separate mathematical flaws in cryptographic algorithms that have eluded detection by human experts for years. In the first case, the AI model reduced the effective key strength of HAWK—a post‑quantum digital signature scheme currently under review by the National Institute of Standards and Technology (NIST)—by half. The second breakthrough involved a seven‑round variant of the Advanced Encryption Standard (AES), where Claude Mythos accelerated the best known attack by a factor of 200 to 800.
Both findings are confined to research‑stage implementations. HAWK has not been deployed in any production environment, and the AES attack targets a reduced‑round version, not the full cipher that protects most of today’s data. Anthropic estimates that each discovery required about $100,000 in API compute resources.
The HAWK weakness emerged after roughly 60 hours of semi‑autonomous work. A single researcher provided project‑management direction while Claude Mythos handled the technical analysis. For the AES result, the model initially resisted attempting an improvement, citing impossibility. After three encouraging prompts over three days, Claude generated a billion output tokens and introduced a technique dubbed the “Möbius Bridge,” which underpinned the faster attack.
Anthropic followed a responsible‑disclosure protocol, sharing the HAWK vulnerability with its authors and coordinating with NIST, the U.S. government, and industry partners before public release. The company also teamed with ETH Zurich, Tel Aviv University, and the University of Haifa to launch CryptanalysisBench, a benchmark suite designed to evaluate AI‑driven cryptanalytic capabilities.
Claude Mythos’s achievements mark a qualitative shift for AI in security. Earlier work by Anthropic exposed implementation bugs in cryptographic libraries, but these new results involve flaws in the underlying mathematics of the algorithms themselves—weaknesses that survived multiple rounds of expert review. In a recent month, Claude Mythos identified 10,000 critical software vulnerabilities, underscoring the rapid expansion of AI’s threat‑modeling reach.
Follow‑up research from Anthropic has already produced additional attacks, including a practical key‑recovery method for 13‑round LEA that runs in under an hour on a desktop, as well as exploits against Serpent‑128, Salsa20, Poseidon, and SHA‑1. The company noted that within a single year, language models have progressed from being unable to tackle basic ciphers to uncovering design flaws that have escaped human discovery for years.
The White House recently launched the Gold Eagle initiative to coordinate AI‑powered cyber‑defense, but Anthropic points out that no comparable program exists for cryptographic review. The firm ends its announcement with a pressing question: what happens when an AI model uncovers a flaw in a cipher that is already protecting live production systems?
Questo articolo è stato scritto con l'assistenza dell'IA.
News Factory APP - notizie agentiche per potenziare il tuo SEO e AEO.