Stephen A. Weis, co-author of Anthropic's HAWK paper, posted an AI-assisted key-recovery attack to the public pqc-forum used in NIST's post-quantum standards process on July 28, crediting Claude Mythos Preview for the finding. The reduction cuts the estimated work for the HAWK-256 challenge parameter set from 2^64 to 2^38. HAWK is not deployed, and the demonstrated recovery applies to a challenge parameter set rather than either of the scheme's two security-level parameters.
What Changed
- Stephen A. Weis posted a Claude Mythos Preview key-recovery attack on HAWK to NIST's public pqc-forum on July 28, cutting the estimated work on the HAWK-256 challenge parameter set from 2^64 to 2^38.
- Cryptographer Daniel Apon replied within an hour that the mathematical reduction checked out independently for him, though The Hacker News reported finding no independent reproduction of the end-to-end HAWK-256 recovery.
- A separate attack on the same scheme, produced with GPT-5.6 by Hengyi Luo, had surfaced 11 days earlier by a mathematically different route and a weaker result.
- Nothing in production changed: HAWK is not deployed, the AES result covers 7 of AES-128's 10 rounds, and NIST has not said whether it will alter HAWK's parameters or standing.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
A Public Forum Check
Daniel Apon, a cryptographer long involved in the NIST process, replied within an hour: "Nice. It checks out independently for me." Apon checked the mathematical reduction. In its review, The Hacker News reported finding no independent reproduction of Anthropic's end-to-end HAWK-256 recovery.
Weis's forum post also lowered the estimated gate-count cost for HAWK-512 from 2^150 to 2^108 and for HAWK-1024 from 2^288 to 2^182. Those attacks remain exponential. Restoring the intended security would require roughly doubling key sizes, according to Anthropic, a change that would remove many of HAWK's advantages as a post-quantum signature candidate. The research blog described the result as specific to HAWK and said it does not affect Falcon, ML-DSA or other lattice-based schemes.
The company reported that the HAWK work took about 60 hours and roughly $100,000 in API spending. NIST advanced HAWK with eight other candidates to the third round of its Additional Digital Signature Schemes process in May.
Luo's July 17 GPT-5.6 Attack
Another model had produced a separate attack on HAWK 11 days earlier. PostQuantum.com reported that Hengyi Luo used GPT-5.6 to mount an attack through adjoint lattice reduction, a mathematically different route from Anthropic's. The anonymous preprint was dated July 17, with Luo's authorship disclosed later in a forum post. Its result was weaker than Anthropic's reduction.
Human cryptographers had also attacked HAWK during the same period. Ben Nelson, Joshua Limbrey, Cong Ling and Andrew Mendelsohn submitted an ePrint paper on June 25 describing a classical key-recovery algorithm under four number-theoretic heuristics. A June 30 update stated that one heuristic was insufficient and that the main algorithm appeared to run in super-polynomial time.
Get Implicator.ai in your inbox
Strategic AI news from San Francisco. No hype, no "AI will change everything" throat clearing. Just what moved, who won, and why it matters. Daily at 6am PST.
No spam. Unsubscribe anytime.
The Reduced-Round AES Result
AES-128 is the symmetric cipher in general use, but Anthropic's result covered only 7 of its 10 rounds. Mythos Preview improved that reduced-round attack by 200 to 800 times, the company reported. The model's Möbius Bridge fingerprint, combined with later optimizations, reduced estimated time complexity from 2^99 to between 2^89.3 and 2^91.4, while still requiring about 2^105 chosen plaintexts. The research blog called that requirement completely impractical.
The full attack was never run. Researchers proved the fingerprint's invariance, formalized part of the proof in Lean and completed key recovery on smaller AES-like ciphers. The model reached its central idea after about three days and then produced about a billion output tokens, according to the company's account. Two company researchers spent several hundred hours verifying the result.
Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.
Forum Rules for AI Claims
In the pqc-forum thread that followed the disclosure, Markku-Juhani Saarinen argued that AI-assisted cryptanalysis should come with machine-checkable proofs or working demonstrations against scaled-down targets. In the same thread, Apon called for a community standard to adjudicate AI-generated cryptanalytic claims, modeled on Scott Aaronson's ten signs.
Glenn S. Gerstell, former general counsel of the National Security Agency, told the New York Times: "Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?"
NIST has not publicly said whether it will change HAWK's parameters, security claims or standing in the process. Anthropic's research blog said the company will host an academic workshop on AI's role in security and cryptography research in the coming weeks.
Frequently Asked Questions
Is any encryption people use today broken by this?
No. HAWK has not been deployed anywhere, and the AES finding applies to a reduced-round variant covering 7 of AES-128's 10 rounds. The attack also assumes roughly 2^105 chosen plaintexts, a requirement Anthropic's research blog called completely impractical.
What exactly did the outside cryptographer confirm?
Daniel Apon confirmed the mathematical reduction posted to the pqc-forum, replying within an hour that it checked out independently for him. That is narrower than reproducing the attack: The Hacker News reported finding no independent reproduction of the end-to-end HAWK-256 key recovery.
How much did the HAWK result cost to produce?
Anthropic reported that the work took about 60 hours and roughly $100,000 in API spending. On the separate AES result, the model reached its central idea after about three days and produced about a billion output tokens, and two company researchers then spent several hundred hours verifying it.
What is the Mobius Bridge?
It is the fingerprinting technique the model produced against reduced-round AES. Combined with later optimizations, it lowered the estimated time complexity from 2^99 to between 2^89.3 and 2^91.4, an improvement Anthropic put at 200 to 800 times over the previous best.
Does this affect other post-quantum schemes?
Anthropic's research blog described the result as specific to HAWK and said it does not affect Falcon, ML-DSA or other lattice-based schemes. NIST has not publicly said whether it will change HAWK's parameters, security claims or standing in the process.
AI-generated summary, reviewed by an editor. More on our AI guidelines.



IMPLICATOR