Safety

Claude Mythos halves
HAWK-256 in 60
hours, forcing NIST
to reckon with
AI cryptanalysis

Anthropic's unreleased Mythos Preview model autonomously found a key-recovery attack on the last lattice-based candidate in NIST's post-quantum signature contest after two years of expert review missed it — and invented a novel technique that speeds a seven-round AES-128 attack by up to 800×.

An unreleased Anthropic model named Claude Mythos Preview autonomously derived a key-recovery attack on HAWK-256, collapsing its expected work factor from 2^64 to 2^38 operations after roughly 60 hours of compute and about $100,000 in API costs. HAWK is the only lattice-based candidate among the nine schemes NIST advanced to the third round of its post-quantum signature competition in May 2026, and it had already survived two rounds of expert human review across two years.

What Mythos did wasn’t invented from nothing. A prior paper by Daniël van Gent and Ludo Pulles had shown that a nontrivial automorphism in HAWK’s lattice would reduce key recovery to finding a short vector in a lattice of roughly half the original dimension. Their work didn’t then affect HAWK. Mythos, according to The Hacker News, found the additional automorphism needed to walk through that door. The human collaborator wasn’t a lattice-cryptography specialist.

The released implementation reconstructs a 592-byte signing key in about three hours and 42 minutes on a 96-core server, and Anthropic says it successfully attacked two included public keys. In its research post, the company said the result “eliminates many of the reasons making the scheme (as it currently stands) an attractive PQC signature candidate.” The obvious remediation, doubling key sizes, is precisely what HAWK was designed to avoid.

The second result is stranger. Researchers barred Mythos from all five established families of AES cryptanalysis and told it to invent a sixth. The model refused, calling improvement impossible, and required three encouraging prompts over three days before proceeding. It then produced roughly one billion output tokens, removed a 256-way guessing step from the existing meet-in-the-middle attack, and delivered a 200- to 800-fold speedup over the 2013 record on seven-round AES-128. It named the technique “Möbius Bridge.” AES-128 was adopted by NIST in 2001; the attack covers only seven of ten rounds and needs impractical chosen plaintexts, so deployed cryptography isn’t at risk.

Neither is HAWK, which isn’t fielded. But the disclosure pattern is what matters here. Anthropic coordinated with NIST, the U.S. government, industry partners, and the algorithm authors before publishing, and released CryptanalysisBench jointly with ETH Zurich, Tel Aviv University, and the University of Haifa. As of July 29, 2026, NIST still lists HAWK as a third-round candidate. Anthropic’s post to the NIST forum has drawn no replies, and no independent reproduction has surfaced.

That silence is the story. Standards bodies move on the timescale of academic consensus; a model that produces a plausible novel attack in a weekend for six figures doesn’t fit inside that clock. The vendor of the model is now, in effect, a participant in the standard-setting process, whether NIST has decided how to treat that or not.

Sources