Source-led article
Anthropic’s Mythos Model Finds Weaknesses in Core Cryptographic Algorithms

Anthropic’s Claude Mythos Preview has uncovered mathematical weaknesses in two foundational cryptographic algorithms that underpin internet security. The model developed an improved attack on HAWK, a post-quantum signature scheme under review by the U.S. National Institute of Standards and Technology (NIST), and a new attack on a reduced version of the Advanced Encryption Standard (AES). According to Anthropic, neither finding compromises systems in use today, but the results demonstrate how AI models could challenge core assumptions behind digital security.
What Mythos Preview achieved
The HAWK attack is particularly significant. HAWK is one of the remaining candidates in NIST’s third-round competition for additional post-quantum signature schemes, designed to remain secure even against future quantum computers. Human cryptographers had reviewed HAWK for more than two years, but Mythos Preview found an improved attack in just 60 hours at an API cost of roughly $100,000. The attack exploits a previously undetected symmetry in the mathematical lattice that HAWK’s security relies on.
Separately, the model developed a new method called “Möbius Bridge” to attack a reduced version of AES-128 that uses 7 of the full scheme’s 10 rounds. AES is the world’s most widely used symmetric encryption standard, securing everything from online banking to messaging. The new fingerprinting technique improves on the best previously known attacks by a factor of 200 to 800.
How the model worked
Mythos Preview operated semi-autonomously in a multi-agent system. One agent initially dismissed the HAWK attack as infeasible, but a second agent found a way to fully exploit it. The human researcher involved had a background in theoretical computer science but was not an expert in lattice-based cryptography. His role was largely limited to project management.
For the AES attack, the model generated several hundred million tokens over three days. Human prompting played a small role: the model initially refused to pursue the problem, stating that further improvements seemed impossible. Only after the researcher encouraged it to look for “genuinely novel ideas” did Mythos begin exploring creative approaches. The run also cost about $100,000 in API fees for roughly 1 billion tokens. Human researchers who were not cryptography experts then spent several hundred hours verifying the results.
Datos clave
| Aspect | Detail |
|---|---|
| Model | Claude Mythos Preview |
| Attack targets | HAWK (post-quantum signature), reduced AES-128 (7 rounds) |
| Time to find HAWK attack | 60 hours |
| API cost per experiment | ~$100,000 |
| Human involvement | Minimal; non-expert researcher managed process |
What it means for internet security
Anthropic says the findings do not affect systems in use today. HAWK is still only a candidate in the NIST review process, and the AES attack applies to a modified, weaker version of the standard. However, the speed and autonomy with which Mythos Preview identified these weaknesses challenge the assumption that cryptanalytic breakthroughs require years of human expertise. The model’s ability to find a vulnerability that human experts missed for over two years suggests that AI could become a powerful tool for both discovering and exploiting cryptographic flaws.
Anthropic shared the findings in advance with the U.S. government and industry partners and coordinated disclosure of the HAWK weakness with the scheme’s authors. The company also developed a benchmark called CryptanalysisBench in collaboration with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa. The benchmark allows systematic evaluation of language models’ cryptanalytic abilities.
Broader implications for India’s tech ecosystem
For India’s rapidly growing digital economy, these developments carry particular weight. The country’s push toward digital public infrastructure, UPI, Aadhaar, and the IndiaAI Mission relies heavily on robust encryption. Indian regulators such as CERT-In and MeitY monitor cryptographic standards closely. While the current findings are not an immediate threat, they underscore the need for Indian cybersecurity researchers, startups, and policy bodies to prepare for a new era where AI can accelerate both the discovery and remediation of cryptographic weaknesses.
Indian tech professionals and researchers should watch how NIST and global standards bodies respond to AI-assisted cryptanalysis. The IndiaAI Mission, which focuses on building sovereign AI capabilities, may also consider funding cryptanalysis research to stay ahead of potential risks.
Source: The Decoder – https://the-decoder.com/anthropic-says-its-mythos-model-found-vulnerabilities-in-cryptographic-algorithms-that-secure-the-internet/