News
AI SHIFT:

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact

Newsroom brief

CyberScoop reported that Anthropic used Claude Mythos Preview to find weaknesses in HAWK and a reduced AES test, while Anthropic stressed that current software remains unaffected.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: CyberScoop
Anthropic Mythos Finds Crypto Flaws Without Real-World Impact
Image source: CyberScoop

An AI cryptanalysis result can now challenge candidate encryption designs before those systems reach production.

CyberScoop's July 28, 2026 coverage found that Anthropic researchers used Claude Mythos Preview to test HAWK, a post-quantum digital-signature candidate, and a reduced version of AES.

Neither flaw affects software now in use, Anthropic emphasised.

AI-assisted research produced meaningful cryptographic attacks, but the public record does not show an immediate route into everyday encrypted systems.

HAWK Finding Tests A Post-Quantum Candidate

The HAWK weakness sits inside a scheme being reviewed by the National Institute of Standards and Technology for encryption that could withstand future quantum-computing attacks.

Working with a human researcher, Claude Mythos found a nontrivial automorphism in the lattice structure that underpins HAWK's security.

The Anthropic paper stated that the shortcut reduces HAWK's effective key strength by half.

Keeping the same security level would require key sizes to double, and Anthropic said that change would remove much of HAWK's appeal as a candidate.

NIST evaluation is designed to expose weaknesses before standards and procurement paths harden.

In Boehm's CyberScoop interview, the research became evidence that the NIST evaluation process is working and that enterprises need maps of where cryptography sits across their business systems.

Reduced AES Test Shows A Faster Theoretical Attack

The second result involved the Advanced Encryption Standard.

NIST adopted AES in 2001, and the cipher is widely used to protect data in transit.

Mythos worked largely on its own and produced a mathematical shortcut called the Möbius Bridge.

Anthropic said real-world AES uses 10 rounds.

The same paper stated that the research target was a simplified seven-round version used to study security margins.

The previous theoretical path required codebreakers to check 256 separate values against a memory table; Mythos eliminated that lookup process.

The Anthropic paper reported that the seven-round attack became 200 to 800 times faster than the prior strongest known theoretical path after the Möbius Bridge was combined with other optimisations.

Anthropic's safety caveat said the attack would require more than 400 octillion target messages and cannot reach the full 10-round encryption protecting everyday systems.

Disclosure Path Keeps The Work In Research Channels

Anthropic's disclosure timeline included notifying HAWK's designers in June, coordinating public release with a NIST mailing list, and briefing government and industry partners before publication.

CryptanalysisBench came from collaboration with ETH Zurich, Tel Aviv University and University of Haifa researchers, creating a shared tool for measuring how AI systems perform against different ciphers.

The disclosure path gives the research an institutional boundary.

HAWK remains a candidate under review, while the AES result applies to a deliberately weakened benchmark used by researchers rather than to production encryption.

Security Teams Get A Cryptography Inventory Problem

Boehm's comments shift the enterprise implication from panic about broken encryption to operational readiness.

Her interview tied AI-driven cryptanalysis to visibility over where cryptography is deployed, which business systems depend on it, and whether companies have a post-quantum readiness plan.

The threat picture stayed cautious.

Five Eyes intelligence agencies warned in June that advanced AI models capable of major cyber disruption were months away, while recent reporting cited by CyberScoop found that AI-assisted bug discoveries have not materially changed the internet-wide threat level.

Government and company response procedures for an AI-discovered critical-infrastructure cryptography flaw remain unresolved in Anthropic's published answer.

Share this article
inXf
Keep Reading

More Stories

Latest
Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.AI Patch Study Keeps Humans In Vulnerability ReviewsCybersecurityAug 7, 2026AI Patch Study Keeps Humans In Vulnerability ReviewsThe Register reported that 1Password Off-by-1 Labs tested 6,080 AI-generated patches across six CVEs and found clean autonomous fixes in 26.0 percent of cases, leaving security teams with a supervision problem rather than a replacement for vulnerability review.