In a landmark moment for both artificial intelligence and cybersecurity, a specialized AI model known as "Mythos," developed by Anthropic, has successfully identified a critical vulnerability in HAWK—a prominent post-quantum cryptographic (PQC) digital signature scheme. The discovery has sent shockwaves through the cryptographic community, leading to the immediate withdrawal of HAWK from consideration as a standard for future US government digital security protocols.

This development marks a departure from traditional, human-led cryptanalysis, signaling an era where AI agents may become the primary architects—and the primary executioners—of cryptographic standards.


Main Facts: The End of HAWK

HAWK, designed to protect digital communications against the looming threat of future quantum computers, had successfully navigated two rounds of rigorous evaluation by the National Institute of Standards and Technology (NIST). Its primary objective was to serve as a robust, future-proof replacement for existing signature schemes that rely on mathematical problems easily solved by quantum algorithms.

However, Mythos, Anthropic’s proprietary security model, uncovered a fatal flaw in the mathematical foundations of HAWK. By utilizing a previously unknown method for finding "automorphism symmetries" within the Lattice Isomorphism Problem—the mathematical bedrock upon which HAWK is built—the AI effectively halved the algorithm’s security strength.

In the world of cryptography, an algorithm is considered "broken" if an adversary can derive a private key significantly faster than via brute-force computation. Following the publication of Anthropic’s findings, the lead developer of HAWK announced the algorithm’s immediate withdrawal, effectively ending its pursuit of NIST standardization.


Chronology of the Discovery

The revelation was not the result of a singular "eureka" moment, but rather a methodical, agentic process orchestrated by Anthropic.

  • Initial Engagement: Anthropic researchers provided Mythos with the specifications for HAWK and a standard set of cryptographic challenge instances.
  • The Investigative Phase: Mythos spent an extensive period performing automated literature reviews to establish the state-of-the-art in lattice-based cryptography.
  • Agentic Collaboration: Anthropic deployed two distinct agents working semi-autonomously. While the first agent initially flagged the proposed attack method as unworkable, the second agent refined the parameters. Through a process of iteration and computational experimentation, the agents reached a consensus on an effective attack vector.
  • Verification: To ensure the validity of the discovery, Mythos autonomously constructed an end-to-end verification pipeline, proving the mathematical viability of the attack before presenting it to human researchers.
  • Public Disclosure: Following the verification, Anthropic announced the results on Monday. By Tuesday, the developer of HAWK had formally conceded, withdrawing the candidate from the NIST selection process.

Supporting Data and Technical Context

The attack against HAWK is particularly notable because it did not require the invention of fundamentally new mathematics. Instead, as noted by Johns Hopkins professor and renowned cryptographer Matthew Green, the AI succeeded by synthesizing existing, well-known tools in a novel, highly efficient configuration.

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

The Attack Mechanics

The HAWK protocol relies on the hardness of the Lattice Isomorphism Problem. Mythos identified a method to exploit the internal symmetries of these lattices. By automating the search for these automorphisms, the AI created a shortcut that reduces the workload for an attacker by 50%.

The AES "Meet-in-the-Middle" Attack

While HAWK was effectively retired, Anthropic also tested Mythos against the Advanced Encryption Standard (AES). While the AES results were less catastrophic, they were nonetheless significant. Utilizing a "Möbius Bridge"—a sophisticated fingerprinting technique—Mythos improved a "meet-in-the-middle" attack.

  • Previous best-known effort: 2^105 plaintext inputs.
  • Mythos-enhanced effort: 2^89 plaintext inputs.
  • Impact: This translates to a 200- to 800-fold increase in efficiency for an attacker, though the attack remains, for now, restricted to laboratory settings using "weakened" versions of the AES specification.

Official Responses and Expert Analysis

The reaction from the cybersecurity community has been a mixture of awe and cautious sobriety.

Sophie Schmieg, a leading expert in Post-Quantum Cryptography at Google, was blunt in her assessment of the HAWK situation: "Basically with this paper, HAWK is dead." Schmieg noted that while HAWK had long been suspected of harboring potential weaknesses, the AI’s ability to pinpoint the exact flaw rendered the algorithm uncompetitive against alternatives like ML-DSA or FN-DSA.

Matthew Green echoed these sentiments, emphasizing the "concerning" efficiency of the AI. "It simply extends a bunch of tools that were lying around and well-known, and gets a good result," Green wrote. He highlighted that this represents a shift where AI, rather than being a "creative genius," acts as an tireless, omnivorous reader capable of finding connections that human researchers—constrained by cognitive load and specialization—often miss.

Anthropic, in their official report, framed the discovery as a wake-up call for the entire industry. "The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up," the company stated.


Implications: The New Frontier of Cryptanalysis

The implications of the Mythos discovery are profound and ripple across several dimensions of modern digital infrastructure.

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

1. The Speed of Vulnerability Discovery

Historically, cryptanalysis has been a slow, academic, and highly human-intensive pursuit. The Mythos breakthrough demonstrates that AI can accelerate the discovery of cryptographic vulnerabilities from years to days. This places an unprecedented burden on the "defenders" of encryption, who must now race against AI agents that never sleep, never tire, and can perform millions of simulations in a single afternoon.

2. The Limits of "Standard" Testing

The fact that HAWK survived two rounds of NIST testing suggests that current adversarial peer-review processes may be fundamentally ill-equipped for the AI era. If an AI can find a flaw that escaped years of expert scrutiny, the certification standards for future cryptosystems will likely need to incorporate "AI-red-teaming" as a mandatory requirement.

3. The "Marketing Hype" Caveat

It is critical to note that Anthropic remains a commercial entity with a vested interest in demonstrating the superiority of its AI models. Critics point out that the company has not yet disclosed whether it has tested Mythos against more entrenched standards like RSA or Elliptic Curve Cryptography (ECC). If the model fails to find similar weaknesses in these older, more battle-tested systems, it may suggest that the HAWK discovery was a "low-hanging fruit" scenario rather than a fundamental shift in the power dynamic between AI and encryption.

4. A Future of Autonomous Research

Anthropic’s prediction that human researchers will soon become the "bottleneck" in the research process is a sobering forecast. As AI models move toward full autonomy—where they do not just assist but actually conduct research—the scientific community will need to develop new frameworks for validating the "technical validity, novelty, and utility" of AI-generated discoveries.

Conclusion: A Race Against the Machine

The retirement of HAWK serves as a definitive case study in the dual-use nature of artificial intelligence. While AI offers the potential to create stronger, more resilient encryption to guard against quantum threats, it simultaneously provides the very tools necessary to tear down the walls we have built.

For the time being, the fundamental building blocks of our digital lives remain secure. However, the "Mythos" event proves that the gap between theoretical security and practical vulnerability is closing. As we move forward, the race to secure our vital assets will no longer be played out between human cryptographers, but between the AI models that protect our data and the AI models designed to unlock it. The era of AI-driven cryptanalysis has arrived, and it has already claimed its first victim.