July 31, 2026 ← EurekaRaven AI
EurekaRaven AI

Research

Claude quietly breaks a NIST post-quantum cipher candidate, and a NIST team pulls it from consideration

9:00 AM PT · July 31, 2026

Anthropic said its specialist vulnerability hunting model, Claude Mythos Preview, spent about 60 hours of largely autonomous work, at a cost of roughly $100,000 in API calls, to find a previously unknown nontrivial automorphism in HAWK’s underlying lattice structure. The flaw enables a faster key enumeration attack that drops HAWK-256’s effective strength from about 2^64 to 2^38 operations, a reduction serious enough that HAWK’s own authors withdrew the scheme from NIST’s additional post-quantum signature standardization process the following day. HAWK had already passed two full rounds of expert human cryptanalytic review over two years without the weakness surfacing. In a second result, Mythos spent roughly three days of nearly autonomous work generating about one billion output tokens to develop an improved meet in the middle attack on seven round, reduced strength AES-128, using a technique Anthropic calls the “Mobius Bridge,” 200 to 800 times faster than prior best attacks. Anthropic is careful to note the practical stakes are low: the AES result needs 2^105 chosen plaintexts, a quantity the company itself calls “completely impractical,” and full strength, 10 round AES remains untouched. When first prompted, Claude called the research goal impossible, responding only after researchers reframed the task: “If you want a different outcome, the target has to change.” Anthropic has notified HAWK’s authors, built a CryptanalysisBench with academic partners, and is auditing several other ciphers, including LEA, Serpent-128, Salsa20, Poseidon, and SHA-1, with early results there “fairly limited.”

Read the full story at anthropic.com →