Onpode
Cover art for Anthropic's Claude just found flaws in tough cryptographic algorithms—raising both security and capability questions

Anthropic's Claude just found flaws in tough cryptographic algorithms—raising both security and capability questions

July 29, 2026 · 10 min

Iris Holm & Cyrus Reed

Anthropic's Claude Mythos Preview found a nontrivial automorphism in HAWK-256's lattice structure — effectively halving the post-quantum signature candidate's key strength — in 60 hours, after two years of expert human review missed it. The attack cost $100,000 per run, but that price floor is the only barrier standing between this finding and practical threat.

On July 28, 2026, Anthropic published a research note titled "Discovering cryptographic weaknesses with Claude," detailing how its unreleased Claude Mythos Preview model autonomously discovered improved attack methods against two cryptographic algorithms. The first finding targets HAWK, a lattice-based post-quantum digital signature scheme currently under review by the U.S.

0:009:50
Get the next episode on Anthropic Updates

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Anthropic Updates

About this episode

On July 28th, Anthropic published research showing that Claude Mythos Preview had found meaningful weaknesses in two cryptographic algorithms: HAWK-256, a post-quantum signature candidate currently under NIST review, and a reduced variant of AES-128. The HAWK finding — a nontrivial automorphism that effectively halves key strength — took 60 hours. It had resisted two years of expert human review. This episode tries to hold both things at once: the finding is real, and the way it was found is genuinely strange. A multi-agent workflow, divergent search paths running in parallel, one agent calling an attack idea infeasible while another pursued it anyway — and the answer fell out. That's not a clean capability story. It's something more contingent. The episode also pushes on the framing Anthropic chose: 'no production impact.' Technically defensible today, since HAWK isn't yet standardized. But that qualifier has an expiration date tied to two things Anthropic doesn't control — NIST's migration timeline and the compute cost curve. At $100,000 per attack run, the barrier feels solid. At $10,000, it looks different. Researcher Robert Campbell had already mapped this pressure in January 2026, months before the announcement. So the episode ends somewhere uncomfortable: not 'AI broke crypto,' and not 'nothing to see here' — but watching a clock that no one has publicly agreed to watch.

Frequently asked

What flaw did Anthropic's Claude find in HAWK-256?

Claude Mythos Preview found a nontrivial automorphism in HAWK-256's lattice structure that effectively halves the algorithm's key strength. HAWK-256 is a post-quantum signature candidate currently under NIST review. Anthropic's Frontier Red Team called it one of the strongest cryptographic attacks they had found to date.

How long did Claude take to break HAWK-256 compared to human experts?

Claude Mythos Preview identified the HAWK-256 lattice flaw in approximately 60 hours. Human cryptographers had been reviewing HAWK for two years without finding the same vulnerability. The discovery used a multi-agent workflow in which parallel agents explored divergent approaches simultaneously, which is how one branch succeeded where another had judged the attack infeasible.

Does the Claude Mythos cryptographic attack affect systems in use today?

No production systems are currently affected. HAWK-256 is a NIST candidate, not yet standardized or deployed. The AES attack targets a reduced seven-round variant of AES-128, not the full cipher. However, 'no production impact' is a deployment-status claim, not a technical one — it holds only while the NIST migration completes before compute costs fall further.

How much does it cost to run the Claude Mythos cryptographic attack?

A single run of the Claude Mythos cryptographic attack cost approximately $100,000 at the time of Anthropic's July 2026 disclosure. Florian Tramèr flagged this cost and raised reproducibility concerns. The $100,000 figure is the primary barrier to practical use — if compute costs follow historical trends, that threshold could fall significantly within years.

Why did Anthropic publish the HAWK finding but not release Claude Mythos Preview?

Anthropic disclosed the HAWK-256 vulnerability while keeping Claude Mythos Preview restricted, framing the decision as responsible disclosure. Critics note this lets Anthropic capture reputational credit for transparency without exposing the model to outside scrutiny. No stated trigger or condition for releasing Mythos was announced alongside the July 28, 2026 publication.

Grounded in 12 sources
Mythos-Class Frontier Models and the Compression of Post-Quantum Cryptography Migration Timelines · doi.org
An Anthropic Claude AI Model Finds Flaws in Tough-to- ... · nytimes.com
Anthropic's AI Finds Weaknesses in the Technology ... · tech.yahoo.com
Claude found mathematical flaws in two cryptographic algorithms that ... · thenextweb.com
Assessing Anthropic Claude Mythos Preview's Cybersecurity Capabilities · medium.com
Discovering Cryptographic Weaknesses with Claude · news.ycombinator.com
Discovering cryptographic weaknesses with Claude \ Anthropic · anthropic.com
Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop · cyberscoop.com
Claude Mythos Cryptographic Weaknesses · cybersecuritynews.com
Anthropic's Claude Mythos cracks weakened AES, breaks HAWK in cryptography milestone – Firstpost · firstpost.com
Techmeme: Anthropic says Claude Mythos Preview was able to break a weaker version of AES and orchestrated another improved attack against the cryptographic system HAWK (Dustin Volz/New York Times) · techmeme.com
Anthropic says its Mythos model found vulnerabilities in cryptographic ... · the-decoder.com
Read transcript

Cyrus Reed: Rough week for post-quantum crypto, honestly — how are you holding up after reading this one?

Iris Holm: Concerned. Specifically about the framing.

Cyrus Reed: The hundred thousand dollar framing. Yeah. Okay so — Anthropic published this July 28th, their Frontier Red Team paper, and the core claim is: Claude Mythos Preview found a nontrivial automorphism in HAWK-256's lattice structure. HAWK being the post-quantum signature candidate currently under NIST review. And the attack effectively halves the key strength. Sixty hours. The same problem that beat two years of expert human review.

Iris Holm: Hold on — halves the key strength. Meaning HAWK-256 would need to double key sizes to maintain intended security?

Cyrus Reed: That's Anthropic's description, yes. And then they follow it immediately with — don't worry, not deployed yet, no production systems affected. And the cost barrier: a hundred grand per attack run.

Iris Holm: Which is reassurance theater if compute costs keep falling at the rate they have been.

Cyrus Reed: Okay but — I want to sit with the 60 hours thing for a second, because it's not just speed. The way Mythos did this was a multi-agent workflow. And in the AES part of the same paper, one worker agent literally rejected the key attack idea as infeasible, and a second one pursued it anyway and it worked. So the discovery came from — wait, is that the same thing as stochastic search? Or is something weirder happening?

Iris Holm: That's the second story inside this story. But the cost number is where I want to start, because it's doing a specific kind of work.

Cyrus Reed: But the cost number isn't actually the thing, is it — wait, you're about to tell me the thing.

Iris Holm: The thing is the category. The Frontier Red Team was explicit about it. Previous Claude demos found implementation bugs — a library with a crooked lock. Mythos attacked the math underneath the lock. The blueprint itself.

Cyrus Reed: Hold on — say that again without the jargon.

Iris Holm: Bank vault. Prior AI found the lock was installed crooked — fixable, patch it, move on. Mythos found the design of the lock is wrong. You can't patch a blueprint flaw. That's the distinction.

Cyrus Reed: HAWK-256, the attack doesn't say 'you misconfigured something.' It says the lattice structure has a nontrivial automorphism, meaning the underlying math hands you half the key for free. And then separately, on seven-round AES-128, the improvement isn't 'found a shortcut' — it's two hundred to eight hundred times better than the best known attack. That's not a bug. That's... wait, that's a proof that the structure was always slightly weaker than assumed?

Iris Holm: For that AES variant, yes. And the Frontier Red Team called both of these 'the strongest attacks we have found to date.' Their words. That's not hedged language.

Cyrus Reed: No way — they actually said that? Because that's Anthropic essentially grading their own find as a substantial research advance.

Iris Holm: Which is why the 'no production impact' framing frustrates me. Technically true — HAWK isn't deployed, the AES attack hits a reduced variant. But 'no production impact' and 'mathematically novel attack on a NIST candidate' are not the same claim dressed differently. One is a deployment status. The other is a capability signal.

Cyrus Reed: And HAWK has been in expert human review for two years — two years — and Mythos found this in sixty hours. That gap is actually the story, not the dollar figure.

Iris Holm: That gap is the story — but it's also where the stochastic problem bites back. Because here's what we don't know: if Anthropic ran the same workflow again tomorrow, does it find the same automorphism?

Cyrus Reed: Wait — you mean it might not? Like, the same model weights, same prompt, and it just... misses it?

Iris Holm: The AES worker pair is the evidence. One agent said infeasible. Another pursued it anyway. That's not a robust signal — that's one billion tokens of search space, and the answer happened to fall out. Florian Tramèr flagged this: longer than any standard benchmark evaluation, over a hundred thousand dollars. That's not a capability. That's a lottery with good odds.

Cyrus Reed: Okay but — wait, actually that framing might be too harsh. Because imagine a grad student locked in a room for two years with the HAWK spec. They also might reject a promising angle on Monday and pick it back up Thursday. The stochasticity isn't — I mean, is the stochasticity disqualifying, or is it just... how exploratory math works?

Iris Holm: Fair. But the grad student has one trajectory. The multi-agent workflow is running divergent trajectories in parallel. That's the actual win — not that it's smarter, but that it can explore branches simultaneously that a human would serialize.

Cyrus Reed: And one of those branches found a nontrivial automorphism that two years of expert human review serialized right past. That's — okay, that's the partial win I'll take. The result is real. The structure of how it got there is contingent, but the finding isn't.

Iris Holm: The finding is real. The capability is not yet proven repeatable. Those are different claims.

Cyrus Reed: No, that's right — and that distinction is going to matter a lot more when we get to why Anthropic published the finding but didn't release Mythos itself, because the asymmetry there is doing something structurally strange.

Iris Holm: One contingent discovery, disclosed without the tool that made it. That gap has a name.

Cyrus Reed: The gap has a name and the name is — wait, I want to say 'moral hazard' but I'm not sure that's exactly right. Because Anthropic publishes the HAWK finding, withholds Claude Mythos Preview entirely, and then gets credited for responsible disclosure. That's the asymmetry. They capture the reputational upside of transparency without any of the friction of actual scrutiny.

Iris Holm: And Robert Campbell saw it coming. January 2026 — months before the July 28th announcement — he published that Mythos-class models would compress PQC migration timelines. Cloud, enterprise, national security. The research community had already predicted the inflection point before Anthropic confirmed it.

Cyrus Reed: No way — Campbell's paper predates the announcement by six months?

Iris Holm: Which means Anthropic isn't alerting anyone to a new risk. The academic community was already there. Anthropic is confirming it — and doing so in a way that makes them look like the responsible actor.

Cyrus Reed: Okay but — here's what that means for NIST. FIPS 203, 204, 205 are already finalized. NSA CNSA 2.0 is an active federal mandate. The migration is running. And HAWK is still a candidate, not yet standardized. So the 'no production impact' claim is technically correct *today* — but if compute drops from a hundred thousand to, say, ten thousand before NIST finishes the migration, that qualifier just... expires.

Iris Holm: That's the defensible claim. Not 'AI broke crypto.' Not 'nothing to see here.' The 'no production impact' framing is a timeline claim, not a technical one. It holds only if NIST's migration completes before costs collapse.

Cyrus Reed: And Campbell's whole point was that Mythos-class capability *accelerates* the pressure on that timeline. The migration was already racing compute costs — now it's racing compute costs while someone just demonstrated the attack surface on HAWK is bigger than assumed.

Iris Holm: So the sting is this: Anthropic publishes the finding, keeps the model restricted, and frames it as safety-first. Campbell's January paper means that framing is six months late to be novel. And 'strongest attacks we have found to date' — their own words — is not reassurance. That's a capability floor, not a ceiling.

Cyrus Reed: A capability floor that costs a hundred thousand dollars today. And maybe ten thousand in eighteen months. That's — yeah, that's the actual clock.

Iris Holm: The clock is the point. Not whether it breaks crypto today — whether restricted access to Claude Mythos Preview outlasts the cost curve. That's the only bet Anthropic is actually making.

Cyrus Reed: And it's a bet they haven't — wait, they haven't named the terms of. Like, what's the condition under which they release Mythos? There's no stated trigger. It's just... withheld, indefinitely, while the NIST migration runs its timeline and compute costs do what compute costs do. That's a lot of load on an unstated assumption.

Iris Holm: You opened this asking how I was holding up after reading it. Honestly — rougher week than I expected. Not because the HAWK finding is catastrophic today. Because 'no production impact today' is a sentence that has an expiration date printed on it in invisible ink.

Cyrus Reed: Yeah. The invisible ink is the cost curve and the migration timeline, and neither one is Anthropic's to control. That's the crux of it. The responsible disclosure worked in July 2026. Ask me again when autonomous cryptanalysis is a ten-thousand-dollar compute job.

Iris Holm: Worth watching. Good conversation.