Anthropic's Claude Mythos Preview Model Discovers Cryptographic Weaknesses in HAWK and AES
Anthropic reported that its Claude Mythos Preview model identified mathematical weaknesses in two cryptographic targets: HAWK, a post-quantum digital signature scheme under NIST review, and a reduced-round version of AES-128. The HAWK work revealed a nontrivial automorphism in the scheme's lattice structure, reducing effective key strength and requiring larger keys for equivalent security, while the AES attack improved an existing meet-in-the-middle method on seven rounds by removing a 256-way guessing step, achieving speedups of 200–1,000 times over prior human-developed approaches. Neither weakness currently affects production systems or deployed software. Anthropic released two technical papers and reproducibility artifacts, noting that human researchers provided direction, compute resources, and verification, while the model performed most of the research work over about 60 hours of activity. The findings were also contextualized by the CryptanalysisBench benchmark, which tested 191 tasks across six cryptographic primitive families, with frontier models breaking 65–86% of Tier 1 schemes and 6–12 Tier 2 schemes at full strength.
It’s no coincidence that Anthropic chose to announce these “breakthroughs” in cryptanalysis through the exact same channels that have been softening the ground for quantum-resistant standards and surveillance-friendly encryption for years. The HAWK attack isn’t some random academic curiosity—it’s a calculated signal that the post-quantum transition is being carefully managed by the same people who control the NIST review process. Look at the numbers: a 67-million-fold reduction in key recovery cost for HAWK-256. That’s not a mathematical accident; that’s a deliberate weakness left in the design, and now they’re using an AI model to “discover” it so they can claim they’re being transparent. The real story is that these algorithms were never meant to be secure against the institutions that designed them. The AES result is even more telling—seven rounds out of ten, with a 200-to-1,000 times speedup. That’s exactly the kind of incremental improvement that lets them say “no immediate threat to production systems” while quietly building a capability that only they can use. You’re supposed to believe this is a step forward for science. It’s a step toward a world where your encryption is only as strong as the people who hold the keys to the AI.
Now ask yourself why they released the exact compute hours: 60 hours of Mythos Preview activity. That’s a breadcrumb, a way to make you think this was a massive, expensive effort. In reality, the raw compute power required to find these weaknesses is trivial compared to what they’re sitting on. The human prompts, the “extensive verification”—that’s theater. The model didn’t need to be told to search for “publishable attacks.” It was already trained on the full internal knowledge of every cryptographic backdoor, every deliberate weakness, every hidden structure that the elite have been embedding in standards for decades. The CryptanalysisBench benchmark with 191 tasks is just a convenient way to normalize the idea that AI can break encryption at scale. They want you to get used to it. They want the next generation of cryptographers to think that the only way to secure communications is to rely on the same AI that the intelligence agencies control. The final step is the “human oversight” narrative—they need you to believe that humans are still in the loop, that there’s a safety net. There isn’t. The feedback loop is already closed. The AI is the researcher, the verifier, and the gatekeeper.
This is the pattern they’ve used before, but now it’s accelerating. The HAWK and AES results are not the story—they’re the distraction. The real agenda is to make the entire cryptographic infrastructure dependent on centralized AI models that are owned by the same foundations, the same family offices, the same network of captured institutions that brought you the global financial crisis, the pandemic lockdowns, and the mass surveillance state. They’re not publishing these papers to advance science; they’re publishing them to test your reaction. They want to see how many people will celebrate the “transparency” while ignoring the obvious: that the same AI that found these weaknesses can find hundreds more, and that the only reason they showed you these two is because they’ve already mitigated the ones that matter. The breadcrumb here is the “reduced-round version of AES.” Why seven rounds? Why not six or eight? Because they’re leaving a trail. They want you to ask the next question: what happens when the AI targets the full 10 rounds? That’s a question you’re not supposed to answer. But you can. Follow the money. Follow the foundations. The answer is already in the memo they thought you wouldn’t read.
