Anthropic's Claude Mythos Preview AI has discovered significant new weaknesses in cryptographic systems. The AI found an attack on HAWK, a post-quantum candidate, reducing the cost to break it by 67 million times and forcing a redesign that negates its advantages. It also surpassed a 2013 record by accelerating an attack on a research version of AES, demonstrating a new AI-assisted workflow that may outpace human vulnerability verification.
HAWK cryptographic vulnerability
- ▪The attack on HAWK reduces the cost of recovering its smallest secret key from 2^64 operations to 2^38, a 67-million-fold reduction
- ▪Fixing the HAWK vulnerability requires doubling its key size, which undermines its primary advantages of compactness and speed
- ▪The Claude model also accelerated an attack on a 7-round research version of the AES cipher by 200 to 800 times
- ▪HAWK is a candidate in the third round of NIST's post-quantum signature competition
AES attack breakthrough
- ▪The AI developed a new technique for the AES attack called a "Möbius Bridge" after being barred from using established methods
- ▪The Claude Mythos Preview model also broke 13 rounds of LEA, a Korean national standard for lightweight encryption, in under an hour
- ▪The new AES attack surpasses a record set by human cryptographers in 2013
Claude Mythos Preview capabilities
- ▪The same model that found the crypto flaws also found 271 vulnerabilities in Firefox during internal testing
- ▪Each cryptographic discovery cost approximately $100,000 in API usage, and Anthropic staff spent several hundred hours verifying the AES work
AI-assisted cryptanalysis workflow
- ▪Anthropic warned that human verification processes may become a bottleneck, struggling to keep up with AI-discovered vulnerabilities
- ▪Anthropic created a benchmark called CryptanalysisBench with 191 cipher-breaking tasks drawn from NIST competitions
- ▪Anthropic's Claude AI discovered new weaknesses in two encryption systems, finding flaws missed by human experts
- ▪The HAWK research paper states that human contribution mainly consisted of directing, organizing, and verifying the AI's work
CryptanalysisBench evaluation
- ▪On CryptanalysisBench, the Mythos 5 model solved 85.7% of tasks with known solutions, while all models scored under 9% against full-strength ciphers
Story comments
Loading comments…