Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
An AI model developed by Anthropic, called Mythos, helped discover a cryptographic weakness in HAWK, a digital signature scheme designed to resist attacks from quantum computers, prompting its developer to withdraw it from consideration as a US government standard. HAWK had already passed two rounds of evaluation by the National Institute of Standards and Technology (NIST) as part of its post-quantum cryptography (PQC) standardisation process, and was undergoing a third round intended to catch exactly this kind of flaw. The finding is notable because it suggests AI systems may now be capable of contributing meaningfully to cryptanalysis, a field with major implications for future digital security.
Working with roughly 60 hours of effort and about $100,000 in computing costs, an Anthropic researcher without cryptography expertise used Mythos to improve upon the best-known existing attack against HAWK, effectively halving its key strength. HAWK's security rests on the presumed difficulty of the Lattice Isomorphism Problem, believed to resist quantum attacks, and Mythos produced a previously unknown method for exploiting so-called automorphism symmetries within it. The weakness could theoretically be mitigated by doubling HAWK's key size, but the resulting performance cost has made the algorithm less attractive and contributed to its withdrawal. Anthropic noted similar, more limited progress was made against the widely used AES cipher, though experts caution the results are incremental, tested against deliberately weakened "challenge" versions of the systems, and do not threaten any cryptography currently in real-world use.
- Anthropic's Mythos AI helped break a candidate quantum-resistant algorithm, HAWK
- HAWK's developer withdrew it after Mythos halved its key strength
- Mythos also made smaller progress attacking the AES cipher
- Experts stress current encryption in use remains unaffected for now