Stephen A. Weis, co-author of Anthropic's HAWK paper, posted an AI-assisted key-recovery attack to the public pqc-forum used in NIST's post-quantum standards process on July 28, crediting Claude Mythos Preview for the finding. The reduction cuts the estimated work for the HAWK-256 challenge parameter set from 2^64 to 2^38. HAWK is not deployed, and the demonstrated recovery applies to a challenge parameter set rather than either of the scheme's two security-level parameters.

What Changed

AI-generated summary, reviewed by an editor. More on our AI guidelines.

A Public Forum Check

Daniel Apon, a cryptographer long involved in the NIST process, replied within an hour: "Nice. It checks out independently for me." Apon checked the mathematical reduction. In its review, The Hacker News reported finding no independent reproduction of Anthropic's end-to-end HAWK-256 recovery.

Weis's forum post also lowered the estimated gate-count cost for HAWK-512 from 2^150 to 2^108 and for HAWK-1024 from 2^288 to 2^182. Those attacks remain exponential. Restoring the intended security would require roughly doubling key sizes, according to Anthropic, a change that would remove many of HAWK's advantages as a post-quantum signature candidate. The research blog described the result as specific to HAWK and said it does not affect Falcon, ML-DSA or other lattice-based schemes.

The company reported that the HAWK work took about 60 hours and roughly $100,000 in API spending. NIST advanced HAWK with eight other candidates to the third round of its Additional Digital Signature Schemes process in May.

Luo's July 17 GPT-5.6 Attack

Another model had produced a separate attack on HAWK 11 days earlier. PostQuantum.com reported that Hengyi Luo used GPT-5.6 to mount an attack through adjoint lattice reduction, a mathematically different route from Anthropic's. The anonymous preprint was dated July 17, with Luo's authorship disclosed later in a forum post. Its result was weaker than Anthropic's reduction.

Human cryptographers had also attacked HAWK during the same period. Ben Nelson, Joshua Limbrey, Cong Ling and Andrew Mendelsohn submitted an ePrint paper on June 25 describing a classical key-recovery algorithm under four number-theoretic heuristics. A June 30 update stated that one heuristic was insufficient and that the main algorithm appeared to run in super-polynomial time.

The Reduced-Round AES Result

AES-128 is the symmetric cipher in general use, but Anthropic's result covered only 7 of its 10 rounds. Mythos Preview improved that reduced-round attack by 200 to 800 times, the company reported. The model's Möbius Bridge fingerprint, combined with later optimizations, reduced estimated time complexity from 2^99 to between 2^89.3 and 2^91.4, while still requiring about 2^105 chosen plaintexts. The research blog called that requirement completely impractical.

The full attack was never run. Researchers proved the fingerprint's invariance, formalized part of the proof in Lean and completed key recovery on smaller AES-like ciphers. The model reached its central idea after about three days and then produced about a billion output tokens, according to the company's account. Two company researchers spent several hundred hours verifying the result.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

Forum Rules for AI Claims

In the pqc-forum thread that followed the disclosure, Markku-Juhani Saarinen argued that AI-assisted cryptanalysis should come with machine-checkable proofs or working demonstrations against scaled-down targets. In the same thread, Apon called for a community standard to adjudicate AI-generated cryptanalytic claims, modeled on Scott Aaronson's ten signs.

Glenn S. Gerstell, former general counsel of the National Security Agency, told the New York Times: "Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?"

NIST has not publicly said whether it will change HAWK's parameters, security claims or standing in the process. Anthropic's research blog said the company will host an academic workshop on AI's role in security and cryptography research in the coming weeks.

Frequently Asked Questions

Is any encryption people use today broken by this?

No. HAWK has not been deployed anywhere, and the AES finding applies to a reduced-round variant covering 7 of AES-128's 10 rounds. The attack also assumes roughly 2^105 chosen plaintexts, a requirement Anthropic's research blog called completely impractical.

What exactly did the outside cryptographer confirm?

Daniel Apon confirmed the mathematical reduction posted to the pqc-forum, replying within an hour that it checked out independently for him. That is narrower than reproducing the attack: The Hacker News reported finding no independent reproduction of the end-to-end HAWK-256 key recovery.

How much did the HAWK result cost to produce?

Anthropic reported that the work took about 60 hours and roughly $100,000 in API spending. On the separate AES result, the model reached its central idea after about three days and produced about a billion output tokens, and two company researchers then spent several hundred hours verifying it.

What is the Mobius Bridge?

It is the fingerprinting technique the model produced against reduced-round AES. Combined with later optimizations, it lowered the estimated time complexity from 2^99 to between 2^89.3 and 2^91.4, an improvement Anthropic put at 200 to 800 times over the previous best.

Does this affect other post-quantum schemes?

Anthropic's research blog described the result as specific to HAWK and said it does not affect Falcon, ML-DSA or other lattice-based schemes. NIST has not publicly said whether it will change HAWK's parameters, security claims or standing in the process.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

OPINION: Take the AI Kill Switch Away From the Politicians
"It's a complete overreaction," Katie Moussouris said of the order that pulled Anthropic's two most capable AI models off the market on Friday. Moussouris, chief executive of the security firm Luta S
Iran Finds the AI Workaround Washington Cannot Sanction
San Francisco | Monday, June 1, 2026 Western AI services now sit inside Iran's cyber and military workflow. The FT says Iranian military and intelligence-linked operators use ChatGPT and Gemini to su
Oracle ships quantum-resistant database with in-place AI agents—and a $1.5B partner bet
Oracle turns the database from storage into runtime, and makes a pre-quantum security play. Oracle has released a major database update that runs AI agents inside transactional systems and adopts pos
AI News

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai