ELECTRONICS·INSIDER
All stories
Semiconductors

Anthropic's Claude Mythos forces HAWK out of NIST's third-round PQC signature process

Anthropic's Claude Mythos Preview halved HAWK's effective key strength in 60 hours on 28 July 2026, prompting the HAWK team to withdraw the scheme from NIST's third-round PQC signature evaluation within 24 hours.

Generated image

On 28 July 2026, Anthropic's Frontier Red Team disclosed that its restricted Claude Mythos Preview model had discovered a structural flaw in HAWK, a lattice-based digital signature scheme under active evaluation by NIST.[1] Within 24 hours, the HAWK team confirmed the finding and withdrew the scheme from NIST's third-round additional signature standardisation process entirely. HAWK had survived two years and two rounds of expert human review before the flaw was found.[1]

What Mythos found in HAWK

HAWK was the only lattice-based scheme among the nine candidates NIST advanced to the third round of its additional post-quantum digital-signature process in May 2026. Claude Mythos Preview, working semi-autonomously inside a multi-agent scaffold with access to Python, Sage, and published cryptographic literature, identified a nontrivial automorphism in HAWK's lattice structure that no human reviewer had exploited. The resulting attack reduced the cost of key recovery on HAWK-256 from approximately 2^64 operations to 2^38, roughly halving the scheme's effective key strength.[1]

The human researcher overseeing the project had a background in theoretical computer science but was not an expert in lattice-based cryptography. Their role was largely managerial - advising Mythos on how to track ideas and which libraries to use for computational verification. The entire HAWK attack took approximately 60 hours of model runtime.[1] Anthropic disclosed the attack to HAWK's authors in June and coordinated simultaneous public disclosure to the NIST mailing list alongside the research release. The HAWK team helped verify the result before disclosure.

A second result: 7-round AES

The same disclosure covered a separate attack on a weakened variant of AES. Working largely on its own, Mythos invented a mathematical shortcut dubbed the "Möbius Bridge." In previous theoretical attacks, codebreakers had to check 256 separate values against a memory table, but Mythos created a shortcut that eliminated that lookup process entirely. Combined with other optimizations, this discovery made the strongest known theoretical attack against seven-round AES 200 to 800 times faster.[1]

Neither finding breaks anything protecting real-world data right now. HAWK has not been deployed anywhere, and the AES result targets a deliberately weakened research variant, not the full cipher running in browsers, banking systems, or encrypted hard drives. Full AES-128 uses 10 rounds; the Möbius Bridge attack targets only 7. The model run cost approximately $100,000 in API usage, but researchers spent several hundred hours checking the method. Anthropic said two researchers took nearly a month to reach confidence that it was correct.

Where the third-round field stands

NIST transitioned nine cryptographic algorithms to the third round of its Additional Digital Signature Selection Project, as detailed in NIST Internal Report IR 8610. The second evaluation round concluded on 14 May 2026, following 18 months of public cryptanalysis, performance benchmarking, and architectural updates.[1] With HAWK withdrawn, eight candidates remain across four mathematical families:

  • Lattice-based: none remaining
  • Isogeny-based: SQIsign
  • MPC-in-the-Head: FAEST, MQOM, SDitH
  • Multivariate: MAYO, QR-UOV, SNOVA, UOV

This third phase of evaluation and review is expected to last approximately two years. NIST is also planning to hold the 7th PQC Standardization Conference in the late spring or early summer of 2027. The already-finalised FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) algorithms are not impacted.

The more consequential question now is whether NIST's review cadence - built around human cryptanalysts working over months - is fast enough when a frontier model can probe a candidate's mathematical foundations in 60 hours for roughly $100,000 in compute. Markku-Juhani Saarinen, writing on the NIST PQC forum, argued that AI-assisted cryptanalysis should always ship machine-checkable proofs or working demonstrations against scaled-down targets - a standard that, if adopted, would reshape how the remaining eight candidates are stress-tested before the 2027 conference.

Written by Electronics Insider's automated desk from the sources above and published automatically. How we work.

Related