Anthropic’s Claude Mythos Preview artificial intelligence identified a critical weakness in HAWK, a candidate for post-quantum digital signatures, just 60 hours after beginning its analysis on July 28, 2026. The HAWK team subsequently withdrew the scheme from consideration by the U.S. National Institute of Standards and Technology.
HAWK had survived two years and two rounds of expert human review. HAWK was unique as the only lattice-based scheme among NIST’s final nine candidates; as Johns Hopkins cryptographer Matthew Green noted, “this is exactly the sort of work that AI systems excel at,” applying existing tools with thoroughness.
The National Institute of Standards and Technology confirmed the AI found the flaw in approximately 60 hours. Operating with access to Python, Sage, and cryptographic literature, the AI discovered a flaw in HAWK’s lattice structure, reducing the cost of key recovery from approximately two to the power of 64 operations to two to the power of 38. This effectively halved the scheme’s key strength, necessitating a doubling of key sizes to restore original security claims, a change that would negate HAWK’s efficiency advantages.
The HAWK team acknowledged this, stating straightforward mitigations would make the scheme uncompetitive. This incident underscores the increasing importance of algorithm agility and comprehensive cryptographic asset discovery for organizations preparing for a post-quantum world.
The resulting attack reduced the cost of key recovery on HAWK-256 from approximately 2^64 operations to 2^38, roughly halving the scheme’s effective key strength.
Anthropic disclosed on July 28, 2026, that its Claude Mythos Preview model discovered a flaw in HAWK within approximately 60 hours. Organizations cannot solely focus on selecting post-quantum algorithms before understanding their existing cryptographic deployments, as classical vulnerabilities currently pose a greater immediate risk than potential quantum attacks.
CipherScout, a product of EQCore, is currently mapping cryptographic assets across ten distinct attack surfaces for organizations, producing a standards-compliant Cryptographic Bill of Materials. Most enterprises, the company asserts, currently lack a complete inventory of their cryptographic assets and associated vulnerabilities. Existing issues like RSA-1024, expired certificates, and weak TLS configurations represent immediate risks, independent of quantum computing threats. This incident highlights that algorithm agility is essential, as organizations that hard-code a single scheme risk being caught unprepared when a candidate fails.
EQCore’s CipherForge offers formally verified PQC implementations based on standardized algorithms, ML-KEM, ML-DSA, and SLH-DSA, rather than those still under evaluation. CipherWatch then provides continuous monitoring, ensuring rapid identification of affected systems should another flaw occur, allowing organizations to respond in hours rather than months.
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
