SendTech Times
News
SYSTEMS SHIFT:

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact

Newsroom brief

CyberScoop reported that Anthropic used Claude Mythos Preview to find weaknesses in HAWK and a reduced AES test, while Anthropic stressed that current software remains unaffected.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: CyberScoop
Anthropic Mythos Finds Crypto Flaws Without Real-World Impact
Image source: CyberScoop

Anthropic researchers used Claude Mythos Preview to attack two cryptographic test targets, but neither finding affects software currently in use.

CyberScoop reported that the experiments covered HAWK, a post-quantum signature candidate, and a reduced version of AES.

The result shows an AI system contributing to cryptanalysis without establishing an immediate threat to deployed encryption.

HAWK Finding Tests A Post-Quantum Candidate

The HAWK weakness sits inside a scheme being reviewed by the National Institute of Standards and Technology for encryption that could withstand future quantum-computing attacks.

Working with a human researcher, Claude Mythos found a nontrivial automorphism in the lattice structure that underpins HAWK's security.

The Anthropic paper stated that the shortcut reduces HAWK's effective key strength by half.

Keeping the same security level would require key sizes to double, and this change would remove much of HAWK's appeal as a candidate.

NIST evaluation is designed to expose weaknesses before standards and procurement paths harden.

In Boehm's CyberScoop interview, the research became evidence that the NIST evaluation process is working and that enterprises need maps of where cryptography sits across their business systems.

Reduced AES Test Shows A Faster Theoretical Attack

The second result involved the Advanced Encryption Standard.

NIST adopted AES in 2001, and the cipher is widely used to protect data in transit.

Mythos worked largely on its own and produced a mathematical shortcut called the Möbius Bridge.

Anthropic said real-world AES uses 10 rounds.

The same paper stated that the research target was a simplified seven-round version used to study security margins.

The previous theoretical path required codebreakers to check 256 separate values against a memory table; Mythos eliminated that lookup process.

The Anthropic paper reported that the seven-round attack became 200 to 800 times faster than the prior strongest known theoretical path after the Möbius Bridge was combined with other optimisations.

Anthropic's safety caveat said the attack would require more than 400 octillion target messages and cannot reach the full 10-round encryption protecting everyday systems.

Disclosure Path Keeps The Work In Research Channels

Anthropic's disclosure timeline included notifying HAWK's designers in June, coordinating public release with a NIST mailing list, and briefing government and industry partners before publication.

CryptanalysisBench came from collaboration with ETH Zurich, Tel Aviv University and University of Haifa researchers, creating a shared tool for measuring how AI systems perform against different ciphers.

The disclosure path gives the research an institutional boundary.

HAWK remains a candidate under review, while the AES result applies to a deliberately weakened benchmark used by researchers rather than to production encryption.

Security Teams Get A Cryptography Inventory Problem

Boehm's comments shift the enterprise implication from panic about broken encryption to operational readiness.

Her interview tied AI-driven cryptanalysis to visibility over where cryptography is deployed, which business systems depend on it, and whether companies have a post-quantum readiness plan.

The threat picture stayed cautious.

Five Eyes intelligence agencies warned in June that advanced AI models capable of major cyber disruption were months away, while recent reporting cited by CyberScoop found that AI-assisted bug discoveries have not materially changed the internet-wide threat level.

Government and company response procedures for an AI-discovered critical-infrastructure cryptography flaw remain unresolved in Anthropic's published answer.

Share this article
inXf
Keep Reading

More Stories

Latest
Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.