
Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet
Quick Answer
Anthropic's Claude Mythos model identified vulnerabilities in cryptographic algorithms, notably improving attacks on the HAWK post-quantum signature scheme and a reduced AES-128 variant, each costing around $100,000 in API fees.
Quick Take
These findings, shared with U.S. authorities, highlight potential challenges to current internet security assumptions.
Key Points
- Mythos found a new attack on HAWK in 60 hours, costing $100,000.
- The AES-128 attack improved known methods by 200 to 800 times.
- Human researchers spent hundreds of hours verifying Mythos' results.
- Findings were shared with U.S. government and industry partners.
- Mythos remains restricted, with no public access yet available.
DeepSignal Analysis
What happened
Anthropic's AI model, Claude Mythos, identified vulnerabilities in cryptographic algorithms, including an improved attack on the HAWK post-quantum signature scheme and a new attack on a reduced AES-128 variant. These findings were shared with U.S. authorities, emphasizing potential challenges to current internet security assumptions.
Key evidence
- Claude Mythos found an improved attack on the HAWK scheme in 60 hours, costing around $100,000 in API fees, despite human experts reviewing it for over two years.
- The attack on a reduced version of AES-128 was developed by Mythos, which initially refused the task but later created a new method called 'Möbius Bridge' that significantly improved attack efficiency.
- Anthropic shared its findings with the U.S. government and coordinated the disclosure of the HAWK weakness with the scheme's authors, while Mythos remains unavailable to the public.
Why it matters
These findings raise concerns about the robustness of current cryptographic standards, particularly as they relate to future quantum computing capabilities. The ability of an AI model to identify vulnerabilities in established algorithms suggests that reliance on traditional security assessments may need reevaluation. The implications for internet security could be significant, as these algorithms are foundational to digital communications and data protection.
Source Excerpt
Anthropic's Claude Mythos Preview found weaknesses in key cryptographic algorithms, including a better attack on HAWK, a post-quantum signature scheme that human experts had reviewed for more than two years. The model found it in just 60 hours at an API cost of about $100,000. The findings don't affect systems in use today, but they show how AI could challenge core assumptions behind internet security, Anthropic says.
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

