Claude Mythos Cracks HAWK Cryptography in 60 Hours
Anthropic's unreleased Claude Mythos Preview halved HAWK signature security in 60 hours for $100K, raising urgent questions about AI-enabled cryptanalysis.
AI Breaks Post-Quantum Cryptography Candidate
Anthropic's unreleased Claude Mythos Preview achieved a breakthrough in cryptanalysis that has alarmed security researchers worldwide. In just 60 hours of work, the AI model improved the best-known attack against HAWK—a digital signature scheme designed to resist quantum computers—effectively cutting its security strength in half. HAWK is currently a third-round candidate in NIST's call for post-quantum cryptographic systems, having already survived two rounds of expert human review over two years. The fact that an AI accomplished in three days what human experts couldn't achieve in 24 months represents a fundamental shift in the cryptanalysis landscape and raises urgent questions about the security of cryptographic systems in the AI era.
Autonomous Discovery With Minimal Human Input
What makes this result particularly concerning is how autonomously Claude Mythos operated. According to the research team, the AI achieved these results mostly without human intervention. One Anthropic researcher collaborated with Claude over the course of a week to develop the HAWK attack, while another researcher built a computational scaffold that allowed Claude to fully autonomously discover an attack against AES encryption. The model demonstrated sophisticated reasoning capabilities, working through complex mathematical problems and cryptanalytic techniques that traditionally require years of specialized human expertise. This level of autonomous capability in such a sensitive domain marks a new frontier in AI-enabled security research—one that could be exploited by malicious actors with sufficient resources.
The $100,000 Security Threat Threshold
Each cryptographic breakthrough discovered by Claude Mythos cost approximately $100,000 in API inference costs to develop. While this might seem like a substantial investment, it represents a frighteningly low barrier for nation-state actors or well-funded malicious groups. As the tweet author notes, misaligned state-level actors would happily spend 10-100 times this amount to compromise critical cryptographic infrastructure. For context, $100,000 is a trivial expense for government intelligence agencies whose budgets run into billions. The economics of AI-enabled cryptanalysis have fundamentally shifted: what once required teams of PhDs working for years can now potentially be achieved in days for the cost of a mid-tier software engineer's annual salary, democratizing advanced cryptanalysis in dangerous ways.
Implications for Cryptographic Standards
The timing of this discovery is particularly critical for NIST's post-quantum cryptography standardization process. HAWK was specifically designed to remain secure against quantum computers, representing humanity's best effort to future-proof digital signatures. If an AI model can halve its security in 60 hours, the entire approach to cryptographic validation may need reconsideration. Traditional security evaluation relies on the assumption that breaking a scheme requires sustained effort from expert cryptanalysts. Claude Mythos has invalidated that assumption. NIST and other standards bodies may need to incorporate AI-based cryptanalysis into their evaluation frameworks, running candidate schemes through adversarial AI systems before standardization. The question is no longer whether human experts can break a scheme, but whether AI can.
The Unreleased Model Security Dilemma
Anthropic faces a delicate dilemma: Claude Mythos Preview remains unreleased, likely because of capabilities exactly like these. The company has demonstrated responsible restraint by not making this model publicly available, yet the research results show why such caution is necessary. This creates a broader tension in AI development: the same capabilities that enable beneficial security research also enable attacks. Unlike previous AI safety concerns focused on misinformation or bias, cryptanalysis capabilities represent a direct, measurable threat to global digital infrastructure. The fact that researchers are publishing these results suggests a belief that transparency about AI cryptanalysis capabilities is necessary for the security community to respond appropriately, even as it signals to adversaries what's now possible with sufficient AI resources.
🎯 Key Takeaways
- Claude Mythos Preview cut HAWK post-quantum cryptography security in half in just 60 hours
- The breakthrough cost approximately $100,000 in API costs—trivial for nation-state actors
- AI operated mostly autonomously, discovering attacks without significant human guidance
- Discovery challenges fundamental assumptions in cryptographic standards validation processes
💡 Claude Mythos Preview's cryptanalytic achievements mark a pivotal moment in both AI capabilities and cybersecurity. The ability to autonomously discover significant attacks against post-quantum cryptographic candidates in days rather than years fundamentally changes the threat landscape. While $100,000 might seem expensive, it represents an accessible price point for sophisticated adversaries. The cryptographic community must now grapple with a new reality: AI models can potentially outpace human experts in finding vulnerabilities, requiring fundamental changes to how we evaluate and trust cryptographic systems in an AI-enabled world.