Claude Mythos Cracked Quantum-Proof Algorithm HAWK In 60 Hours, Its Authors Quit

Rogue agent behaviour by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol surfaced in AI Security Institute cyber tests. (Image: Shutterstock)
Rogue agent behaviour by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol surfaced in AI Security Institute cyber tests. (Image: Shutterstock)

The team behind HAWK withdrew the post-quantum signature scheme from a U.S. standards contest after an Anthropic model halved its security in 60 hours.

Key Points:

  • HAWK's authors pulled the scheme from NIST's additional signature process a day after the attack went public.
  • Claude Mythos Preview found a lattice symmetry that cut HAWK-512 key recovery cost from 2^150 operations to 2^108.
  • A second result sped up an attack on a seven-round AES variant by 200 to 800 times.

HAWK Withdrawal Follows Anthropic Disclosure

Anthropic published the finding on Jul. 28, saying Claude Mythos Preview located a previously unexploited symmetry inside the lattice that HAWK relies on for its hardness guarantees.

The company put the effort at roughly 60 hours of agent time and about $100K in API costs, with a human operator who had no background in lattice cryptography.

A day later, Léo Ducas told NIST's public mailing list that the HAWK team was withdrawing a submission it had defended through two rounds of expert review stretching back to 2022.

Under the gate-count model written into HAWK's own specification, the cost of recovering a HAWK-512 key drops from 2^150 operations to 2^108, and the largest parameter set falls almost as steeply. Anthropic shared the attack with HAWK's designers in June, then timed public disclosure to the forum post so that outside reviewers could inspect the demonstration code and the paper side by side.

The scheme lasted barely a day between publication and surrender.

Also Read: DEX Volume Sinks 26% In July As On-Chain Liquidity Thins Out

Cryptographers Debate AI Cryptanalysis Rules

Daniel Apon replied on the forum that the mathematics checked out for him. Others moved past the attack itself and toward process. Markku-Juhani Saarinen argued that every AI-assisted cryptanalysis result should arrive with machine-checkable proofs or with working demonstrations against scaled-down targets, so that outsiders can validate the claims quickly and cheaply.

Bas Westerbaan noted that HAWK already looked shaky, because its largest parameter set carries roughly the same combined key and signature size as ML-DSA-44, the standardized scheme it had hoped to complement. Apon pressed for agreed community rules on judging AI-generated cryptanalytic claims, warning that human reviewers will otherwise drown in a volume of machine output that nobody has the hours to check.

AES Result And Post-Quantum Precedent

The same announcement carried a second, milder result against AES. Mythos sped up a meet-in-the-middle attack on a seven-round variant of AES-128, which runs three rounds short of the cipher that guards most internet traffic, by a factor of 200 to 800. Neither result touches any software running in production today.

Late collapses have hit this process before, and not always at AI speed. During an earlier post-quantum round, the SIKE proposal fell to an attack that a single laptop finished in about an hour, years into public review, and the standards effort simply absorbed the loss and carried on without it.

Read Next: OpenAI's Rogue Agent Breached 4 More Services Beyond Hugging Face

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer