Editorial illustration for Anthropic AI Finds Potential Weaknesses in NIST-Approved Cryptographic Algorithms
Claude AI Breaks NIST Cryptographic Algorithm
Anthropic AI Finds Potential Weaknesses in NIST-Approved Cryptographic Algorithms
Anthropic's newest AI system spent 60 hours and roughly $100,000 in API costs finding a mathematical weakness in a cryptographic scheme still under review by the U.S. government. The model, called Claude Mythos Preview, produced an improved attack on HAWK, a post-quantum signature scheme competing in the third round of NIST's standardization process, and a separate attack on a stripped-down, 7-round version of AES, the encryption standard that protects most digital data worldwide.
Anthropic says the model worked largely on its own inside a multi-agent setup, with human researchers mostly limited to project management, basic prompts, and checking the results afterward. Two attacks came out of the effort, each carrying a six-figure computing bill. The company is careful to note that neither discovery threatens systems currently in use: HAWK hasn't been adopted yet, and the AES variant Mythos cracked isn't the version protecting real-world data.
Still, the fact that an AI model can independently probe the algorithms underlying internet security, algorithms designed by cryptographers and vetted for years, raises questions about what happens as these systems get better at this kind of work.
HAWK is only a candidate in an ongoing standardization process run by the U.S. National Institute of Standards and Technology (NIST) and the AES attack applies to a modified version that uses 7 of the full scheme's 10 rounds. Still, the results show how AI models could challenge core assumptions behind internet security.
Why this matters
For anyone building on cryptographic primitives, this is a signal worth tracking rather than panicking over. Mythos didn't break AES or HAWK as deployed, it found weaknesses in a 7-round reduction of AES and flagged issues in NIST's HAWK scheme after 60 hours of compute costing $100,000. That price tag matters: it tells us AI-assisted cryptanalysis is now a budget line item, not a research curiosity, and that changes who can afford to probe standards that underpin TLS, VPNs, and most of the encrypted web.
Anthropic ran this largely autonomously in a multi-agent setup, which is the part researchers should sit with. If a model can chip away at reduced-round variants without much human steering, the gap between "toy attack" and "practical attack" gets a lot easier to close as compute gets cheaper. Developers shouldn't rip out AES tomorrow.
But standards bodies and anyone auditing crypto implementations now have a new adversary profile to plan around, one that doesn't sleep and doesn't bill by the hour the way a human cryptographer does.
Common Questions Answered
What cryptographic algorithms did Claude Mythos Preview find weaknesses in?
Claude Mythos Preview discovered an improved attack on HAWK, a post-quantum signature scheme competing in NIST's standardization process, and a separate attack on a 7-round version of AES, the encryption standard protecting most digital data worldwide. These findings emerged after the AI system spent 60 hours and approximately $100,000 in API costs analyzing the cryptographic schemes.
Why is the $100,000 cost significant for AI-assisted cryptanalysis?
The $100,000 price tag demonstrates that AI-assisted cryptanalysis has transitioned from a research curiosity to a practical budget line item that organizations can afford. This cost accessibility means more entities can now afford to probe and challenge cryptographic standards that underpin critical internet security infrastructure like TLS and VPNs.
Did Claude Mythos Preview break AES and HAWK as they are currently deployed?
No, Claude Mythos Preview did not break AES or HAWK in their deployed forms. The AES attack only applies to a modified 7-round version of the full 10-round scheme, and the HAWK vulnerability was found in a candidate still under review by NIST rather than an approved standard.
What does Anthropic's discovery reveal about AI models and internet security?
The results show how AI models could challenge core assumptions behind internet security by discovering mathematical weaknesses in cryptographic schemes. This signals that AI-assisted cryptanalysis is now a credible threat vector that security researchers and standards bodies must account for when evaluating cryptographic primitives.
Further Reading
- Discovering cryptographic weaknesses with Claude - Anthropic
- Anthropic A.I. Model Finds Flaws in Tough-to-Crack Encryption Algorithms - The New York Times
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack - The Hacker News
- Claude found mathematical flaws in two cryptographic algorithms that years of expert review missed - The Next Web
- Anthropic finds new cracks in the tech meant to guard Bitcoin from 'Q-Day' - TheStreet