Claude Mythos breaks HAWK and nibbles AES-7: Anthropic publishes its report on autonomous crypto research

Cybersecurity 1 h agoAdd to bookmarks

Claude Mythos breaks HAWK and nibbles AES-7: Anthropic publishes its report on autonomous crypto research
Illustration : Momiji Shirogane

Anthropic ran Claude Mythos Preview as a semi-autonomous agent on cryptographic primitives: effective keysize of HAWK-256 dropped from 2^64 to 2^38, 7-round AES attack accelerated ×200 to ×800, LEA 13-round key recovery in less than an hour. Two real CVE (OpenSSL, wolfSSL) along the way. Cost: ~$100,000 API per subject.

The facts

Anthropic published a research report on July 28, 2026, describing the use of Claude Mythos Preview (not Opus) as a semi-autonomous agent to analyze cryptographic primitives. The audited targets cover post-quantum schemes, classical block ciphers, and hash functions:

  • HAWK (post-quantum signature, NIST candidate) - effective keysize halved, attack cost on HAWK-256 reduced from 2^64 to 2^38. Coordination with NIST and the scheme's authors in June 2026.
  • AES-128 (7 reduced rounds) - attack 200 to 800 × faster than the state of the art, elimination of a guess requirement.
  • LEA (Lightweight Encryption Algorithm, 13 rounds) - key recovery with less than 2^30 encrypted plaintexts, executable in less than an hour on a desktop.
  • Serpent-128 (6 rounds) - extension of a full key-recovery attack.
  • Other targets audited: Salsa20, Poseidon, SHA-1.

In parallel, two real CVEs on production libraries:

  • CVE-2026-45445 in OpenSSL
  • CVE-2026-5194 in wolfSSL

The analysis - what the agent actually does

The setup is important to understand: it's not Claude who "breaks" AES all by himself in one night. It's a semi-autonomous methodology - scaffolding with Python, Sage (the open-source mathematical CAS), access to published crypto literature. Humans frame, restart, guide. One of the most honest quotes from the report: « the models tend to think it is impossible to solve so they don't try » - you have to actively push the model against its own refusal to try.

The costs and deadlines give the measure:

  • HAWK: ~60 hours agent, ~$100,000 in API
  • AES: ~3 days agent, ~$100,000 in API
  • Human verification: several hundred hours; « it took two researchers nearly a month to gain confidence that the method it discovered is correct »

Translation: the machine produces plausible candidates; humans still have to prove that it's correct. We are very far from the buzzword « AI breaks AES ». We are closer to the tireless, expensive, and monitored post-doc intern, but who finds real things.

The attacked rounds (7 on AES, 13 on LEA, 6 on Serpent) are reduced versions - a standard exercise in academic cryptanalysis. AES-128 in production use remains 10 rounds: the announced flaw does not break your TLS tomorrow morning. However, gaining a 200-800× factor on 7-round is a publishable methodological advance, and the report passes the peer-review bar.

On HAWK, on the other hand, reducing a post-quantum candidate from 2^64 to 2^38 before standardization is the kind of result that directly influences NIST's decision - hence the coordination as early as June 2026.

What this changes

Three concrete things:

  1. Responsible disclosure on crypto enters a new phase. Anthropic says it has shared the results in advance with US government and industrial partners. Crypto teams will need to integrate LLM agents into their audit threat model, not just their attacker threat model.

  2. The cost per subject (~$100k) excludes hobbyists and sets the bar at the level of funded labs - but these labs include intelligence agencies, not just defensive vendors. To be considered for non-standardized schemes.

  3. AES-128 in production remains solid. Don't change your TLS config this weekend.

What to do now

Encadré - to do now

  • If you are following the NIST post-quantum standardization: read the HAWK report before betting on this scheme.
  • Patch CVE-2026-45445 (OpenSSL) and CVE-2026-5194 (wolfSSL) according to your vendor advisories.
  • For cryptographers: the paper details the scaffolding and the prompts - reproducible, if not cheap.
  • For CISOs: integrate « crypto audit by LLM agent » into the next threat cycle.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

20 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information