Anthropic Mythos Finds Crypto Flaws Without Real-World Impact
CyberScoop reported that Anthropic used Claude Mythos Preview to find weaknesses in HAWK and a reduced AES test, while Anthropic stressed that current software remains unaffected.

An AI cryptanalysis result can now challenge candidate encryption designs before those systems reach production.
CyberScoop's July 28, 2026 coverage found that Anthropic researchers used Claude Mythos Preview to test HAWK, a post-quantum digital-signature candidate, and a reduced version of AES.
Neither flaw affects software now in use, Anthropic emphasised.
AI-assisted research produced meaningful cryptographic attacks, but the public record does not show an immediate route into everyday encrypted systems.
HAWK Finding Tests A Post-Quantum Candidate
The HAWK weakness sits inside a scheme being reviewed by the National Institute of Standards and Technology for encryption that could withstand future quantum-computing attacks.
Working with a human researcher, Claude Mythos found a nontrivial automorphism in the lattice structure that underpins HAWK's security.
The Anthropic paper stated that the shortcut reduces HAWK's effective key strength by half.
Keeping the same security level would require key sizes to double, and Anthropic said that change would remove much of HAWK's appeal as a candidate.
NIST evaluation is designed to expose weaknesses before standards and procurement paths harden.
In Boehm's CyberScoop interview, the research became evidence that the NIST evaluation process is working and that enterprises need maps of where cryptography sits across their business systems.
Reduced AES Test Shows A Faster Theoretical Attack
The second result involved the Advanced Encryption Standard.
NIST adopted AES in 2001, and the cipher is widely used to protect data in transit.
Mythos worked largely on its own and produced a mathematical shortcut called the Möbius Bridge.
Anthropic said real-world AES uses 10 rounds.
The same paper stated that the research target was a simplified seven-round version used to study security margins.
The previous theoretical path required codebreakers to check 256 separate values against a memory table; Mythos eliminated that lookup process.
The Anthropic paper reported that the seven-round attack became 200 to 800 times faster than the prior strongest known theoretical path after the Möbius Bridge was combined with other optimisations.
Anthropic's safety caveat said the attack would require more than 400 octillion target messages and cannot reach the full 10-round encryption protecting everyday systems.
Disclosure Path Keeps The Work In Research Channels
Anthropic's disclosure timeline included notifying HAWK's designers in June, coordinating public release with a NIST mailing list, and briefing government and industry partners before publication.
CryptanalysisBench came from collaboration with ETH Zurich, Tel Aviv University and University of Haifa researchers, creating a shared tool for measuring how AI systems perform against different ciphers.
The disclosure path gives the research an institutional boundary.
HAWK remains a candidate under review, while the AES result applies to a deliberately weakened benchmark used by researchers rather than to production encryption.
Security Teams Get A Cryptography Inventory Problem
Boehm's comments shift the enterprise implication from panic about broken encryption to operational readiness.
Her interview tied AI-driven cryptanalysis to visibility over where cryptography is deployed, which business systems depend on it, and whether companies have a post-quantum readiness plan.
The threat picture stayed cautious.
Five Eyes intelligence agencies warned in June that advanced AI models capable of major cyber disruption were months away, while recent reporting cited by CyberScoop found that AI-assisted bug discoveries have not materially changed the internet-wide threat level.
Government and company response procedures for an AI-discovered critical-infrastructure cryptography flaw remain unresolved in Anthropic's published answer.












