Claude Mythos Preview helps Anthropic find weaknesses in HAWK and 7-round AES-128

In Crypto Regulations
July 29, 2026

Claude Mythos Preview helps Anthropic find weaknesses in HAWK and 7-round AES-128

Claude Mythos Preview helped Anthropic researchers identify two cryptanalytic attacks — on the HAWK post-quantum digital signature scheme and a reduced-round AES-128, the company said.

“These are significant research advances, but they have no practical impact on today’s systems. […] both results show that advanced AI models can conduct research in cryptography at an expert level,” the post said.

Anthropic stressed the findings do not affect live systems and do not require changes to production software.

HAWK is a candidate for standardization as a post-quantum digital signature scheme. Such signatures are used to verify the author of a message or transaction without revealing the private key.

AES-128 is one of the most widely used symmetric ciphers. It uses a single secret key for encryption and decryption. The full AES-128 consists of 10 rounds of transformations, while Anthropic’s result concerns only a reduced 7-round version used in academic testing.

According to the company, each of the two studies cost roughly $100,000 in API spend. Searching for, developing, and validating the HAWK attack took about 60 hours, while confirming the AES result required several hundred researcher-hours.

HAWK attack reduced estimated security

Anthropic said Claude Mythos Preview found a previously unused symmetry in HAWK’s mathematical structure. It enabled a faster key-recovery attack.

In a technical paper, Anthropic described this as a reduction in effective key strength. For HAWK-256, the expected cost of full key recovery dropped from 2^64 to 2^38 operations. For HAWK-512 and HAWK-1024, the attack remains effectively infeasible.

The company said that to maintain the previous protection level, HAWK would need to roughly double key sizes. In Anthropic’s view, this weakens one of the scheme’s advantages — compactness. The researchers also emphasized the result does not carry over to other NIST candidates and does not imply a general break of lattice-based post-quantum cryptography.

AES speedup limited to research scenario

The second result concerns 7-round AES-128. Anthropic described a method the authors call Möbius Bridge.

According to the company, Claude Mythos Preview improved the previous strongest known meet-in-the-middle attack on 7-round AES. The speedup was roughly 200–800x, depending on how execution time is counted.

The scenario remains impractical. It assumes a chosen-plaintext model: an attacker can repeatedly send preselected data for encryption and receive the result. In the described line of work, 2^105 such queries were required.

Anthropic said the new work does not break full AES-128 and does not affect similar production schemes. Even for the reduced version, the attack remains a research result rather than a practical tool against modern systems.

The company said Claude Mythos Preview found the idea for AES in about a week. Researchers then needed almost a month to verify the result’s correctness.

For HAWK, verification was simpler: Anthropic released demonstration code and described end-to-end key recovery for HAWK-256. For AES, the full attack cannot be run directly due to its enormous computational cost, so the authors tested individual components and reduced variants.

The company said it disclosed the results in advance to the algorithms’ authors, U.S. government bodies, and industry partners. For HAWK, Anthropic notified the scheme’s creators in June and coordinated publication with the NIST mailing list.

Dedicated benchmark for models

To assess the cryptanalytic capabilities of language models, Anthropic, together with researchers from ETH Zurich, Tel Aviv University, the University of Haifa, and TU Berlin, introduced CryptanalysisBench.

The benchmark includes 191 tasks across six families of cryptographic primitives, primarily from NIST competitions. Models must not only explain vulnerabilities but also submit a working attack script that passes formal verification.

According to the authors, five tested frontier models solved 65–86% of Tier 1 tasks. Claude Mythos 5 achieved 85.7%, while the weakest tested AI assistant scored 65.3%.

On full schemes without published practical attacks, results were much lower: no model exceeded 9% in that category.

Снимок экрана — 2026-07-29 в 11.56.38
Comparison of models on Tier 1 and Tier 2. Source: arXiv.

Anthropic reports other findings

Separately, Anthropic said Claude Mythos Preview found an attack on 13 rounds of the Korean block cipher standard for resource-constrained devices, LEA. According to the company, it can recover a 13-round LEA key in under an hour on a modern desktop computer.

The full version uses 24 rounds, so this result also does not pose an immediate risk to active systems, Anthropic emphasized. The company added that the LEA work appeared after the main results, and it is still studying details, including exact bounds on the number of required texts and applicability to 14 rounds.

In May, Anthropic reported the first results of a vulnerability-hunting program using Claude Mythos. Over a month, about 50 partners identified more than 10,000 high- and critical-severity security issues.

In July, Dreadnode researchers identified a systematic rule bypass in cyber benchmarks by language models. In both cases, the central challenge remains verifying results produced by AI agents.

Avatar photo
/ Published posts: 823

Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.