Claude Mythos Cracks Post-Quantum Cryptography: HAWK Signature Attack and AES Findings
Anthropic says its unreleased “Claude Mythos” Preview model discovered two previously unknown cryptographic attacks, including a post-quantum cryptography break affecting HAWK— a digital signature candidate in NIST’s post-quantum signature competition.
For HAWK, Claude found a symmetry that reduced the work to recover the smallest key from 2^64 operations to 2^38 (about 67 million times less). Anthropic notes that fixing the flaw would require roughly doubling HAWK’s key size, which could weaken HAWK’s attractiveness as a practical post-quantum cryptography option because compact signatures and fast signing were central to its pitch.
Separately, Claude accelerated an attack on a 7-round version of AES by 200–800x, beating a long-standing cryptographers’ record from 2013. Anthropic emphasizes the result targets a reduced AES version (not a fully deployed standard), and verification took hundreds of hours of human review. The model also broke 13 rounds of LEA (a lightweight encryption standard), but the real 24-round deployments were not broken.
Anthropic coordinated disclosures with HAWK’s authors and NIST before publishing. The company also argues this shows AI-assisted vulnerability discovery can outpace human triage and verification, and it introduced “CryptanalysisBench” to benchmark fully automated cipher-breaking.
For traders, the key point is timing: HAWK is not deployed, and Bitcoin still uses ECDSA. The post-quantum cryptography development affects future replacement planning more than today’s chain security.
Neutral
Neutral because the reported breaks target future migration candidates, not live blockchain usage. HAWK is a NIST post-quantum cryptography contender but has not been deployed anywhere; Bitcoin still runs ECDSA, so there is no immediate “walk-back” of active security. The market reaction to similar announcements in the past (e.g., incremental changes to hashing/mining standards or PQC candidate revisions) has typically been muted unless an actually deployed scheme is shown vulnerable.
Short term: traders may see minor sentiment noise in “quantum resistance” and infrastructure narratives, but no direct risk repricing should follow because the practical deployment link is missing.
Long term: the need to modify HAWK parameters (likely larger keys and different trade-offs) can shift the timeline and cost of post-quantum upgrades across ecosystems. If NIST’s selected candidates change, developers and exchanges may adjust roadmaps, which could marginally influence demand for compliance/security tooling and related adoption stories—however, that is unlikely to be strongly reflected in crypto prices immediately.