Onpode
Cover art for Anthropic's latest Claude model just cracked weakened AES and broke HAWK in a major cryptography milestone

Anthropic's latest Claude model just cracked weakened AES and broke HAWK in a major cryptography milestone

July 29, 2026 · 8 min

Tess Hollis & Felix Ortiz

Claude Mythos Preview found a lattice automorphism that halves HAWK's effective security in 60 hours — a NIST post-quantum candidate that survived two years of expert review. The same model invented the Möbius Bridge technique, speeding up a known AES attack by 200–800×. The entire discovery, naming, and threat assessment came from Anthropic alone, with no independent cryptographic verification.

On July 28, 2026, Anthropic published "Discovering cryptographic weaknesses with Claude," reporting that its frontier model Claude Mythos Preview had autonomously discovered meaningful structural flaws in two cryptographic systems.

0:007:51
Get the next episode on Technology

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Technology

About this episode

On July 28th, Anthropic published a paper describing how its Claude Mythos model found a meaningful flaw in HAWK — a post-quantum encryption scheme currently in NIST's third-round review process. The flaw is mathematical: an unexpected symmetry in HAWK's lattice structure that roughly halves the scheme's effective security. NIST's own cryptographers had been reviewing HAWK for two years without finding it. Mythos found it in about 60 hours. This episode works through what that actually means — and what it doesn't. The AES result, a 200–800x speedup on a reduced-round variant using a novel technique Mythos named the Möbius Bridge, is a research finding on a practice model, not a threat to deployed encryption. The HAWK result is different. HAWK is a real candidate that could become a deployed standard, and the attack that halves its security now runs in under four hours on a cloud server you can rent. The episode also sits with a harder question: every layer of this story — the discovery, the naming, the threat assessment, the timing — was controlled by Anthropic, about Anthropic's own model, with no publicly named independent verification. That's not a reason to dismiss the finding. But it is a reason to think carefully about what 'responsible disclosure' requires when the disclosing party is also the only one who's checked the math.

Frequently asked

Did Claude AI break HAWK encryption?

Claude Mythos Preview found a nontrivial lattice automorphism in HAWK that roughly halves its effective security strength. HAWK is a NIST post-quantum third-round candidate. Anthropic's key-recovery attack on HAWK-256 runs in three hours and forty-two minutes on a 96-core server. No independent cryptographer has publicly verified the finding.

What is the Möbius Bridge attack technique?

Möbius Bridge is a cryptanalytic method invented by Claude Mythos during its attack on a reduced-round AES variant. It eliminates a 256-way guessing step from an existing meet-in-the-middle attack, speeding up the best-known approach by 200 to 800 times. Anthropic published the method on July 28th; it is now publicly available.

How much did it cost Anthropic to crack HAWK with AI?

Anthropic's Claude Mythos attack on HAWK cost approximately $100,000 in API usage. That is within reach of a mid-size cybersecurity firm's annual research budget. The HAWK-256 key-recovery attack then runs in three hours and forty-two minutes on a rentable 96-core cloud server, requiring no specialized expertise beyond running the model.

Is HAWK still a NIST post-quantum standard candidate after this attack?

Yes. As of Anthropic's July 28th disclosure, HAWK remains a NIST third-round post-quantum candidate and no final standard has been issued. The automorphism Claude Mythos found halves HAWK's effective security, but NIST's review process is ongoing and no independent mathematician has publicly confirmed the result.

Should organizations be worried that AI can now break encryption?

The AES attack targeted a weakened seven-round research variant, not the full deployed standard. The HAWK finding is more serious — HAWK is a real standardization candidate — but Anthropic assessed the immediate real-world threat as low. That assessment came solely from Anthropic, with no published independent cryptographic verification, which is a meaningful caveat.

Grounded in 10 sources
Claude Mythos Cracked Post-Quantum Cryptography That ... · tech.yahoo.com
An Anthropic Claude AI Model Finds Flaws in Tough-to- ... · nytimes.com
Anthropic A.I. Model Finds Flaws in Tough-to-Crack ... · nytimes.com
Discovering cryptographic weaknesses with Claude \ Anthropic · anthropic.com
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack - Cybernoz · cybernoz.com
Anthropic's Claude Mythos finds weaknesses in encryption ... · cyberscoop.com
Anthropic's Claude Mythos cracks weakened AES, breaks HAWK in cryptography milestone – Firstpost · firstpost.com
AI Cracks Post-Quantum Cipher in 60 Hours After Two ... · techtimes.com
Anthropic says its Mythos model found vulnerabilities in cryptographic ... · the-decoder.com
AI Finds New Weaknesses in Cryptographic Algorithms, Anthropic Says · thequantuminsider.com
Read transcript

Felix Ortiz: Tess, hey — long week or just a weird one?

Tess Hollis: Weird. I kept coming back to this Anthropic thing and getting more irritated each time, which is usually a sign we should talk about it.

Felix Ortiz: The HAWK paper.

Tess Hollis: Claude Mythos Preview finds a nontrivial automorphism in HAWK's lattice structure — something that roughly halves the scheme's effective security — in about 60 hours. NIST's own reviewers, actual cryptographers, spent two years on HAWK and didn't find it.

Felix Ortiz: And HAWK is a third-round candidate, so it's not like NIST threw amateurs at it.

Tess Hollis: Wait, that's the part I actually want to sit in — because Anthropic's Frontier Red Team publishes this on July 28th, frames it as a responsible disclosure, and immediately tells us not to worry. But who verified that verdict? No independent cryptographic expert is named in the paper.

Felix Ortiz: Right, and that's — yeah, I've been wrestling with that. Because I do think responsible disclosure is genuinely working here in some sense, but the 'don't worry' landing is Anthropic's own judgment about Anthropic's own finding.

Tess Hollis: So does this prove the standardization process works — flaw caught before deployment — or does it prove the process can't keep pace with what's now possible?

Felix Ortiz: Both. That's actually — okay, both are true simultaneously, which is the uncomfortable answer. But let me back up one level, because I think the AES piece is where it clicks. Think of AES like a combination lock with ten spinning dials. The seven-round variant that Claude Mythos attacked? Seven dials. Nobody puts that on a bank vault. That's the research model, the practice lock sitting on a workbench.

Tess Hollis: Okay, so the lock Mythos cracked isn't the lock on anything real.

Felix Ortiz: Right, exactly — but the Möbius Bridge technique that Mythos invented to do it? That's not a seven-dial thing. That's a general method. It eliminated a 256-way guessing step from an existing meet-in-the-middle attack, sped up the best-known approach by 200 to 800 times. Claude named it. The model named its own attack.

Tess Hollis: Wait — the 200 to 800 times speedup is on the practice lock, though.

Felix Ortiz: Yes. And — yeah, that's the tension. And HAWK is different, right? HAWK is a real candidate, NIST third-round, could become an actual deployed standard. And there, Mythos found a nontrivial automorphism in the lattice structure — an unexpected symmetry that halves the effective security strength. That one is not on a practice lock.

Tess Hollis: In 60 hours. On a scheme two years of expert review didn't crack.

Felix Ortiz: And Anthropic's implementation of the HAWK-256 key-recovery attack runs in three hours and forty-two minutes on a 96-core server. Like — that's a specific machine you can rent.

Tess Hollis: Okay, but the Möbius Bridge is published. It's named, it's out there, it's generalizable. You're telling me this is a contained lab result and simultaneously handing me the method. Which is it?

Felix Ortiz: Yeah, and I don't think Anthropic has a clean answer to that. They called these the strongest attacks they've found to date — and they're clear it's math, not buggy software, the algorithms themselves — but publishing the technique while saying 'don't worry' is doing two things at once that don't fully fit together.

Tess Hollis: But that's the door I want to kick open, because 'don't worry' only works if the gap between research result and real-world threat is wide enough to matter. HAWK survived two years of NIST expert review. Sixty AI-hours later, it's halved. Who's assuming that gap stays wide?

Felix Ortiz: Yeah, and — okay, I've been trying to figure out if the $100,000 API cost is reassuring or terrifying, and I honestly can't land on one.

Tess Hollis: Walk me through who Anthropic thinks can afford that.

Felix Ortiz: That's the — wait, no, that's exactly the problem. $100,000 is not a nation-state budget. That's a mid-size cybersecurity firm's annual research line item. That's a well-funded grad student. And if you pair that with the fact that the HAWK-256 key-recovery attack runs in three hours and forty-two minutes on a 96-core cloud instance — I mean, imagine a security analyst, Sunday night, company credit card, spins up a 96-core server, and has results before Monday morning standup. That's the actual scenario.

Tess Hollis: And Anthropic names that price and moves on.

Felix Ortiz: They do. And the multi-agent setup means the humans involved were mostly doing project management and simple prompts — the mathematical discovery was Mythos running largely on its own. So the cost isn't even buying you expertise. It's buying you the model doing the expertise.

Tess Hollis: Which means the constraint isn't skill anymore. It's just budget. And the compression problem — 60 hours versus two years — that's not a speed record. That's a signal that standardization timelines are built for human review cycles that AI just... skips.

Felix Ortiz: Right — and NIST's process assumes roughly how long it takes a human expert to find something. If that baseline just collapsed, the whole review timeline is calibrated to the wrong instrument.

Tess Hollis: And that's before we even get to the part I think makes this worse — who exactly gets to decide what Anthropic's own model discovered, what it means, and when the world hears about it. That's coming.

Felix Ortiz: And that's — okay, that's the part I've been trying to be honest about. Anthropic's Frontier Red Team discovered this. Anthropic named it. Möbius Bridge is their model's name for its own technique. Anthropic decided when July 28th was. Anthropic told us what the threat level means. That's every layer of the story in one set of hands, with zero independent cryptographic verification anywhere in the published record.

Tess Hollis: No outside mathematician has walked through the HAWK lattice attack and confirmed the security halves.

Felix Ortiz: Not publicly, no. And I'll concede that straight — you're right about that gap. But here's where I want to make the strongest case I actually have: NIST's whole post-quantum standardization process exists for exactly this. Find the flaw before HAWK is a deployed standard, not after. And that happened. The process worked.

Tess Hollis: It worked — but only because Anthropic chose to surface it.

Felix Ortiz: Right, but — wait, no, that's actually the implication that matters more to me than the conflict-of-interest question. If Claude Mythos can do this in 60 hours for $100,000, then NIST's next candidate review shouldn't be waiting to see if a private lab happens to run the attack first. AI-driven cryptanalysis needs to be a built-in part of the evaluation toolkit. Required. Before approval, not after a paper drops.

Tess Hollis: Okay — that part I'll take. That's the strongest version of your case.

Felix Ortiz: I mean, imagine a NIST cryptographer in the third-round review, fall of 2027, and instead of two years of manual analysis she has a Mythos-class model running structured lattice attacks for six weeks as a standard line item. The HAWK automorphism gets found in house. Anthropic never controls that story.

Tess Hollis: What you still haven't answered is whether Anthropic publishes the next one — or just quietly uses it.

Felix Ortiz: Yeah, and — that's actually the thing I keep landing on and not resolving. Because Anthropic published the Möbius Bridge method on July 28th. It's out. Anyone can read it. HAWK is still a NIST third-round candidate — the review is ongoing, nothing's finalized — and the technique that halves its security is just... sitting there, public, for whoever wants it.

Tess Hollis: Right — but that's the question I can't fully answer, and I don't think you can either. In six months we'll know if NIST accelerated the HAWK review, we'll know if another lab reproduced the Möbius Bridge result on a different candidate, we'll know if anyone actually built a working attack from what Anthropic published. But if all three of those are yes — at what point does responsible disclosure become someone else's operational playbook? And who's even watching for that moment?

Felix Ortiz: I don't have a clean answer to that.

Tess Hollis: Neither do I. And I think that's actually where this one ends for me — not with a verdict, just with that question sitting there.