Anthropic Claude AI Model Cuts HAWK Security by Half, Prompting Withdrawal From NIST Quantum Crypto Standard
The HAWK research team withdrew a post quantum digital signature scheme from the National Institute of Standards and Technology standardization process Tuesday after its security margin was cut in half. The reduction followed a 60 hour key recovery attack developed by Anthropic Claude Mythos Preview.
Claude also identified a weakness in a reduced version of the Advanced Encryption Standard, speeding up a known attack by 200 to 800 times. Anthropic said the two discoveries, which cost roughly $100,000 in API usage, do not affect software currently in operation. The company published the technical details Tuesday and worked with academics to create a benchmark for testing AI models on cryptanalysis.
From the sources (22 posts)
@anthropicaiNew Anthropic research: Discovering cryptographic weaknesses with Claude. Claude Mythos Preview has helped our researchers find weaknesses in cryptographic algorithms—the mathematical methods that are used to keep data private. Read more:
@anthropicaiClaude discovered weaknesses in a highly-secure digital signature scheme (used to verify identity digitally) and a well-known symmetric cipher (used to encrypt data).
@anthropicaiThe digital signature scheme is HAWK, which is designed to be robust even against hypothetical quantum computers. HAWK has survived two years of expert review, but in 60 hours Mythos Preview found a previously-unknown attack that reduced t
@anthropicaiThe symmetric cipher is a reduced version of the Advanced Encryption Standard (AES)—which has received decades of scrutiny (more than almost any other encryption algorithm). In a week, Mythos Preview found a way to speed up an attack on th
@anthropicaiMythos Preview did most of this work autonomously, with occasional human guidance. Each of the two results cost roughly $100,000 in API usage. We disclosed the findings in advance to the algorithms’ authors, as well as to US government and
@anthropicaiThese are substantial research advances, but they don’t have a practical impact on today’s systems. HAWK is a proposed scheme that hasn’t been deployed anywhere, and the AES attack we discovered was on a weaker version and does not break th
@anthropicaiStill, both results show that frontier AI models are capable of doing expert-level cryptography research. This has important defensive applications—testing the algorithms that keep our online activity secure, and ultimately helping to make
@anthropicaiFull technical details of both attacks are provided in our new papers: On HAWK: On AES: And the associated model chain-of-thought for AES:
@anthropicaiWe also worked with academics at ETH Zurich, Tel Aviv University, and the University of Haifa to build CryptanalysisBench, a benchmark for studying LLMs’ cryptanalysis abilities.
@degeneratenewsNEW: @AnthropicAI ANNOUNCES THAT RESEARCHERS, USING CLAUDE MYTHOS PREVIEW, FOUND IMPROVED WAYS TO ATTACK CRYPTOGRAPHIC ALGORITHMS - THE MATHEMATICAL METHODS THAT SAFEGUARD ONLINE DATA PRIVACY ONE ATTACK SIGNIFICANTLY WEAKENS HAWK (A POST-Q
@cointelegraph🚨 BIG: Anthropic’s Claude helped researchers discover weaknesses in a highly secure digital signature scheme and a well-known symmetric cipher used to encrypt data.
@nic_carterSomething I (and many others) have been saying. It’s not about “pre and post quantum”, it’s about exiting the golden era of ECC and moving into the new crypto agile era thanks to AI + Q. Rapid progress in math means rapid progress destroy
@nic_carterClaude found holes in a candidate PQ algorithm; not one that has been put forth as a potential option for any blockchain and one in which theoretical vulnerabilities were already known. This doesn’t undermine the need to move to PQ, just re
@matthew_d_greenA few people have asked about the Anthropic Hawk and AES cryptanalysis results. The top-level answer is: It’s very impressive. Three immediate comments on the actual results, old-school thread below.
@coinmarketcapLATEST: 🚨 Anthropic’s Claude Mythos Preview found a major weakness in a post-quantum cryptography candidate that survived two years of expert review, doing it in just 60 hours.
@mlstreettalkRT @AnthropicAI: New Anthropic research: Discovering cryptographic weaknesses with Claude. Claude Mythos Preview has helped our researcher…
@cyberscoopnewsAnthropic researchers used Claude Mythos Preview to find new weaknesses in two cryptographic methods, the company said Tuesday, including one that is being considered by the National Institute of Standards and Technology for both traditiona
@daveaitelRT @matthew_d_green: A few people have asked about the Anthropic Hawk and AES cryptanalysis results. The top-level answer is: It’s very imp…
@matthew_d_greenIn case you missed the previous thread, I wrote up a short blog post giving my thoughts on the new Anthropic cryptanalysis results against HAWK and AES.
@thehackersnewsRT @TheHackersNews: ‼️ BREAKING — Claude AI found a working HAWK-256 key-recovery attack. HAWK is a NIST post-quantum cryptography candida…
@daveaitelRT @matthew_d_green: In case you missed the previous thread, I wrote up a short blog post giving my thoughts on the new Anthropic cryptanal…
@thehackersnews⚡ UPDATE — The HAWK team has withdrawn its post-quantum digital-signature scheme from NIST’s standardization process after confirming #Anthropic's key-recovery attack sharply reduced its security margin. NIST now lists HAWK as withdrawn.