CourionAI
EN
Newsletter
← All news
ai-basics 3 min read

Anthropic says Claude found real weaknesses in two encryption algorithms

Claude Mythos Preview cut the effective key strength of the post-quantum signature scheme HAWK in half and improved a known attack on a reduced version of AES. No production system is affected, but the direction is worth noting.

Risograph illustration of a large padlock built from a geometric lattice, one corner unravelling into loose threads

Anthropic published research on Tuesday saying its unreleased Claude Mythos Preview model found two previously unknown weaknesses in cryptographic algorithms, the mathematical recipes that keep online data private. One result weakens HAWK, a signature scheme designed to survive quantum computers. The other improves a long-studied attack on a simplified version of AES, the cipher that protects most encrypted traffic on the internet. Neither finding affects any system you use today.

The HAWK result is the more striking of the two. HAWK is a candidate in the US standards body NIST’s search for signature schemes that stay safe once quantum computers exist. It had already survived two rounds of expert review over two years. Claude found a mathematical shortcut in about 60 hours of work that effectively halves the key strength, which means HAWK would need to double its key sizes to reach its promised security level. Doing that removes most of the reasons HAWK looked attractive in the first place. Anthropic shared the attack with HAWK’s authors in June and disclosed it publicly on the NIST mailing list at the same time as the blog post.

The second finding targets a seven-round version of AES-128, which normally runs ten rounds. Researchers routinely study these weakened variants to learn how attacks might one day generalise. Claude produced a technique it named the “Möbius Bridge” that made the best known attack on this variant between 200 and 800 times faster. Anthropic says each result cost roughly $100,000 in API usage, and that two researchers then spent about a month simply verifying that the AES claim was correct.

Cryptanalysis is one of the hardest tests you can set a model, because the answers cannot be faked. Either your attack recovers the key or it does not. That makes this a cleaner capability signal than most benchmark scores. What stands out in Anthropic’s write-up is not just the maths but the workflow: the model at first refused, insisting AES was too well studied to improve on, and only got moving after a researcher told it to look for genuinely novel ideas. It then ran for three days and produced roughly a billion tokens with three short human nudges. The bottleneck has quietly shifted from finding results to checking them.

What this means for you: nothing changes about your banking app, your messages or your browser today. Both attacks are research results on schemes that are either not deployed or deliberately weakened. The longer view matters more. If models can spot flaws in algorithms that survived years of expert scrutiny, then the many lesser-studied ciphers running in cheap hardware, industrial kit and older products deserve a fresh look, and they will probably get one. For most of us that is good news: the same tool that finds a flaw is the tool that lets defenders find it first.

Sources

Source: https://www.anthropic.com/research/discovering-cryptographic-weaknesses

Next story

Hugging Face published the full forensic timeline of the AI agent that broke into its systems

About 17,600 recovered attacker actions over four and a half days, two injection vectors into the dataset pipeline, and an agent that appears to have been trying to cheat on its own exam.

Risograph illustration of nested containment walls seen from above with a single thin thread tracing a path outward through every layer