AI cryptanalysis compresses flaw-finding time from months to hours.

Claude Mythos Preview identified a mathematical flaw in HAWK, a candidate for NIST’s Additional Digital Signatures standardization process, after the scheme had already withstood two years and two rounds of human expert review. Researchers from ETH Zurich, Anthropic, Tel Aviv University, and TU Berlin demonstrated the accelerating pace of change with CryptanalysisBench, where five AI models broke 65 to 86 percent of easier tasks and six to twelve full-strength schemes in the harder tier, the company says.

This compression of effort, reducing analysis timelines from months or years to hours or days, signals a shift in who can discover cryptographic weaknesses, and at what cost. “The gap between discovery and a usable patch has already compressed from years to hours for implementation vulnerabilities,” notes Anthropic, suggesting a similar trajectory for algorithmic weaknesses.

Claude Mythos Preview Breaks HAWK and Improves AES Attack

The HAWK cryptographic scheme was withdrawn from consideration for standardization by NIST days after Claude Mythos Preview revealed a mathematical flaw, a vulnerability undetected through two years of prior expert review. Anthropic’s AI model located the weakness in approximately 60 hours, demonstrating a significant compression of the timeline for identifying cryptographic vulnerabilities, according to the company. This rapid discovery highlights a shift from manual analysis to AI-assisted cryptanalysis, impacting the standardization process for digital signatures. Beyond HAWK, the Claude Mythos Preview model also achieved a notable improvement in attacking a reduced-round variant of AES. The AI developed a technique, dubbed the Möbius Bridge, that accelerated the best existing attack on 7-round AES by a factor of 200 to 800. While full AES-128 and AES-256 remain secure, the speedup highlights the increasing efficiency of AI in probing cryptographic designs. Each of these analyses required approximately $100,000 in computing resources, a cost that may become increasingly accessible as AI tools mature. These findings, stemming from largely autonomous model work, suggest a fundamental change in the balance between attackers and defenders.

Cryptographic Bill of Materials Reveals Enterprise Blind Spots

Anthropic researchers detailed on July 28, 2026, that Claude Mythos Preview identified two cryptographic weaknesses, a finding that emphasises a growing disparity between the speed of vulnerability discovery and the time needed to implement effective defenses. The company noted that many ciphers currently protecting live systems have received insufficient scrutiny and may harbor undiscovered vulnerabilities. As AI cryptanalysis capabilities expand, these weaknesses may surface faster than organizations can apply patches, receive responses from standards bodies, or replace affected systems. This rapid pace of discovery highlights a critical blind spot for most enterprises: a lack of precise knowledge regarding which cryptographic algorithms protect which systems, and which systems would fail if a given algorithm were replaced. An effective crypto-agility risk assessment establishes an organization’s true ability to respond to vulnerabilities, rather than its perceived agility, by evaluating three key capabilities.

A Cryptographic Bill of Materials, or CBOM, maps every algorithm, key, certificate and protocol across an organization’s entire digital estate, including TLS, VPNs, PKI, HSMs, code-signing pipelines and third-party platforms. Organizations typically discover three to five times more cryptographic dependencies than initially estimated when conducting a thorough CBOM analysis.

Crypto-Agility Enables Algorithm Replacement Without Re-Engineering

A crypto-agility risk assessment moves beyond perceived readiness to reveal an organization’s true capacity to respond to vulnerabilities, establishing a measurable baseline for cryptographic resilience. Unlike traditional methods of assessing security posture, this evaluation focuses on the three core capabilities that define agility: discovery, preparation and adaptation. Systems designed without crypto-agility demand code rewrites when cryptographic algorithms require replacement, a process that introduces significant delays and potential for error. In contrast, systems built with algorithm selection abstracted into version-controlled configuration need only policy updates, transforming a potentially lengthy re-engineering project into a simple configuration change. NIST defines crypto-agility as the capability to replace cryptographic algorithms without rebuilding the surrounding architecture, a property increasingly vital in the face of accelerating threats. Building hybrid deployment into migration paths, running classical and post-quantum algorithms in parallel, preserves interoperability while minimizing exposure to newly discovered weaknesses.

The organizations best positioned to withstand future cryptographic incidents will not be those that initially selected the most secure algorithms, but those that have engineered systems capable of rapid adaptation. The shrinking interval between the discovery of a cryptographic weakness and its public disclosure is outpacing most organizations’ replacement cycles, a trend dramatically accelerated by advances in AI-driven cryptanalysis, the company says. Encryption has always been a race, and artificial intelligence has simply increased the speed of the opposing side, demanding a fundamental shift in how organizations approach cryptographic security.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Dr. Donovan

Latest Posts by Dr. Donovan: