{"id":8925,"date":"2026-07-29T15:17:06","date_gmt":"2026-07-29T15:17:06","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8925"},"modified":"2026-07-29T15:17:06","modified_gmt":"2026-07-29T15:17:06","slug":"mythos-takes-its-first-shot-at-post-quantum-cryptography","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8925","title":{"rendered":"Mythos takes its first shot at post-quantum cryptography"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Anthropic\u2019s Claude <a href=\"https:\/\/www.csoonline.com\/article\/4198019\/claude-mythos-faq-capabilities-access-competitors-implications.html\">Mythos<\/a> Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms.<\/p>\n<p class=\"wp-block-paragraph\">One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the other improves the best previously known attack against a weakened version of the widely used Advanced Encryption Standard (<a href=\"https:\/\/www.csoonline.com\/article\/548682\/encryption-crypto-is-cracked-how-not-to-fall-in.html\">AES<\/a>).<\/p>\n<p class=\"wp-block-paragraph\">Neither finding compromises production deployments nor weakens the security of real-world systems. Instead, Anthropic said, the findings improve the understanding of the security margins of modern cryptographic designs.<\/p>\n<h2 class=\"wp-block-heading\">Security margin reduced<\/h2>\n<p class=\"wp-block-paragraph\">Hawk is among the post-quantum cryptographic (<a href=\"https:\/\/www.csoonline.com\/article\/4142174\/pqc-roadmap-remains-hazy-as-vendors-race-for-early-advantage.html\">PQC<\/a>) schemes under consideration by the US National Institute of Standards and Technology as it evaluates <a href=\"https:\/\/csrc.nist.gov\/projects\/pqc-dig-sig\">additional algorithms<\/a> designed to withstand attacks from quantum computers, and like some previously evaluated submissions relies on lattice-based cryptography.<\/p>\n<p class=\"wp-block-paragraph\">\u201cDespite Hawk having survived two rounds of expert human review over a period of two years, Mythos was able to improve the best-known attack on it in just 60 hours of work,\u201d Anthropic said in a <a href=\"https:\/\/www.anthropic.com\/research\/discovering-cryptographic-weaknesses\">blog post about its research<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic only studied the 256-bit version of Hawk, while the submission NIST is evaluating concerns the 512- and 1024-bit versions. However, said Anthropic, its findings are still relevant.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe key sizes proposed in the HAWK submission are significantly weaker than originally suggested,\u201d it said in its blog post, but for larger keys, Hawk \u201cremains impractical to attack.\u201d<\/p>\n<p class=\"wp-block-paragraph\">On the other hand, the post said, <a href=\"https:\/\/anthropic.com\/document\/hawk_key_recovery.pdf\" target=\"_blank\" rel=\"noopener\">Anthropic\u2019s attack<\/a> makes Hawk less practical to use because it effectively halves Hawk\u2019s security level, meaning substantially larger key sizes will be required to restore its intended security. Such an increase would diminish many of the efficiency benefits that made Hawk an attractive post-quantum signature candidate, Anthropic wrote.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic\u2019s new finding \u201cis specific to Hawk and does not impact other NIST post-quantum signature candidates or lattice-based cryptography in general,\u201d the company wrote.<\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/anthropic.com\/document\/aes_mobius_bridge.pdf\" target=\"_blank\" rel=\"noopener\">second attack<\/a> is based on a new cryptanalytic technique, dubbed \u201cMobius Bridge,\u201d which improves attacks against a weakened version of AES-128 using only seven \u201crounds\u201d instead of the full-strength version\u2019s 10. Rounds are the repeated series of mathematical transformations that AES and other encryption algorithms apply to protect data. Security researchers commonly study reduced-round variants to evaluate the security margins of block ciphers like AES.<\/p>\n<p class=\"wp-block-paragraph\">Anthropic said the new technique improving the speed of the previous best attacks by 200-800 times previous attacks on the reduced-round construction while remaining well short of threatening the full versions of AES used in production.<\/p>\n<h2 class=\"wp-block-heading\">No practical application<\/h2>\n<p class=\"wp-block-paragraph\">Anthropic explicitly stated that the research has no practical impact on the security of deployed AES implementations \u2014 and for good reason.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe attack operates under a chosen plaintext threat model, which is the most common assumption used for studying ciphers like AES,\u201d it explained in the blog post. This assumes that an attacker is able to request that the defender encrypt arbitrary inputs with a fixed, unknown key, and then gets to see the corresponding output. In this case, it assumes the attacker can request the encryption of 2^105 (about 4 billion billion billion) chosen plaintexts. \u201cThis attack is therefore completely impractical but quantifies the attack cost against AES under these assumptions,\u201d it said.<\/p>\n<p class=\"wp-block-paragraph\">Claude Mythos Preview discovered the attack almost entirely autonomously, Anthropic said, adding, \u201cA researcher at Anthropic built a scaffold that enabled Claude to pose hypotheses, run experiments to experimentally validate or refute these hypotheses, and then asked Claude to design an attack that improves on the best cryptanalysis of AES.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Even with AI accelerating some parts of the research, more time is spent verifying the correctness of results. The improved attack on AES was discovered in about a week, but took two researchers nearly a month to validate, Anthropic said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Anthropic\u2019s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the other improves the best previously known attack against a weakened version of the widely used [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8926,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8925","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8925"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8925"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8925\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8926"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8925"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8925"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8925"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}