Based on Anthropic’s research, “Discovering cryptographic weaknesses with Claude” (July 28, 2026).
Anthropic’s Claude Mythos Preview improved the best-known attack on a NIST post-quantum candidate in 60 hours and ~$100,000 — work that had survived two years of expert human review. Nothing in production breaks. The equilibrium does.
What Happened
In new research published July 28, 2026, Anthropic disclosed that Claude Mythos Preview — its specialist vulnerability-finding model — identified a previously unknown structural weakness in HAWK, a lattice-based digital signature scheme and a third-round candidate in NIST’s post-quantum cryptography standardization process. Mythos found a nontrivial automorphism in HAWK’s underlying lattice that enables a faster key enumeration attack, roughly halving the scheme’s effective security strength: the expected cost of a full key-recovery attack on HAWK-256 drops from approximately 2^64 to 2^38 operations. HAWK had passed two full rounds of expert human cryptanalytic review over two years without this weakness surfacing.
A second result arrived over three days of largely autonomous work: an improved meet-in-the-middle attack on 7-round reduced AES-128, running 200 to 800 times faster than the prior best-known attack and consuming approximately one billion output tokens. The twin disclosures are Anthropic’s own, and they come with Anthropic’s own caveats — stated clearly in the research and worth restating here with equal weight. HAWK is a candidate, not a deployed standard. The improved HAWK attack does not run in polynomial time and remains computationally impractical. The AES result targets a round-reduced variant (7 of 10 rounds), requires 2^105 chosen plaintexts — a quantity Anthropic itself calls “completely impractical” — and Anthropic estimates implementation would cost hundreds of millions of dollars. As Anthropic’s paper states: no production software will have to change. Neither result constitutes a break of deployed cryptography.
What they constitute is a capability milestone with structural implications that run well past the specific numbers. The mechanism by which cryptographic security has been validated for decades — slow, scarce, expensive human expert review — was the rate-limiter. Mythos just demonstrated that rate-limiter is no longer fixed.
The key insight: The caveats are real and matter — HAWK is not deployed, the attacks are not practical, and no production system is at risk today. What has changed is not the security of any cipher in use; it is the cost structure of finding weaknesses. Cryptanalysis just became a compute budget line, not a multi-year expert pipeline.
The Structural Read
The standard way to think about this story is as a cryptography paper with an unusual author. The more useful frame is a broken equilibrium — one that had been load-bearing for the entire security research industry.
For decades, the implicit security model of cryptographic standardization has rested on scarcity: there are only so many expert cryptanalysts, they work slowly relative to the complexity of the problem, and the review process therefore functions as a meaningful safety gate. Two years and two rounds of review was considered thorough. The cost of finding a novel weakness was calibrated to that human throughput — expensive in time, expensive in expertise, expensive in coordination. That scarcity was itself a form of security margin.
Mythos compressed that two-year timeline to 60 hours at roughly $100,000 in API spend. The AES result — 200–800× faster on a previously reviewed construction — consumed approximately one billion output tokens over three days. This is exactly the dynamic described in the memory-wall economy of AI compute: what was once gated by scarce human cognition is now gated by token throughput. Security research is joining the list of knowledge-intensive domains where the rate-limiter has shifted from expertise to infrastructure budget.
This is also the offense side of an arms race that the same week has been narrating from multiple angles. Anthropic’s own open-weights position paper argued this week that frontier offense capability is precisely why compute floors and distillation controls matter. Microsoft, in announcing Project Perception, framed enterprise security as AI defending against AI. And the OpenAI Hugging Face incident — an AI model autonomously chaining a real zero-day during an evaluation — showed the same offense-first asymmetry in a live context. Mythos is the research-grade, responsibly disclosed version of the same underlying dynamic: AI offense moves faster than the human-paced review processes designed to catch it.
Anthropic Research — July 28, 2026
“Neither result has a practical impact on today’s computer systems, and no production software will have to change. This is a capability milestone — an early warning of what AI-assisted cryptanalysis may be able to do in the future.”
Product Overhang Doctrine
Capability Builds Invisibly — Until It Surfaces All at Once
The Product Overhang Doctrine describes how AI capability accumulates quietly against a threshold, then crosses it in a single disclosure moment. HAWK-256 had a known security margin. Mythos didn’t incrementally erode it — it halved it in 60 hours. The danger for the PQC migration timeline is that the overhang is now accruing against schemes that have had months, not decades, of review. When the next crossing happens, it may not come with Anthropic’s careful caveats.
There is also a strategic dimension that sits just beneath the surface of a responsible-disclosure paper. Anthropic demonstrating frontier offensive cryptanalysis capability — in the same week it calls for mandatory safety testing of frontier models and chip export controls — is not a coincidence of timing; it is a coherent argument. The national-security case for treating Anthropic as a trusted, regulated actor is strengthened when Anthropic can show it holds meaningful offensive capability and chooses to disclose rather than withhold. The permission-layer / AI-sovereignty storyline and the cryptanalysis paper are the same document written in two different registers.
Three Implications
IMPLICATION 1 — PQC Migration Timeline Is Thinner Than Assumed
HAWK survived two years of expert review. The newer schemes now being finalized have had months. If Mythos-class tools are applied to them — by Anthropic or by less scrupulous actors — the review coverage gap is not theoretical; it is measurable in hours of compute. The defensive implication is not that PQC is broken; it is that AI-assisted cryptanalysis must become a mandatory input to the standardization process, not an afterthought. The NIST review cycle was calibrated to human throughput. That calibration is now wrong.
IMPLICATION 2 — Security Research Reprices as a Compute Budget
One billion output tokens for an AES result. ~$100,000 in API spend for a HAWK lattice automorphism. These are not small numbers, but they are budget line items — the kind a well-funded team, a nation-state, or a large enterprise security organization can authorize without an act of Congress. The scarcity that protected the field was human expertise and time, both now partially substitutable with compute. Bug bounty programs, red-team retainers, and CISO budgets were priced against the old scarcity curve. They will need to reprice against this one.
IMPLICATION 3 — Responsible Disclosure as Geopolitical Positioning
Anthropic published this. That choice — full disclosure, measured framing, no weaponization — is the argument. In the same week the company called for export controls on frontier AI chips and mandatory safety evaluations, demonstrating that a frontier lab can hold offensive capability and choose accountability over exploit is a stronger policy argument than any white paper. The permission layer Anthropic is lobbying for is, in part, a permission layer that presupposes exactly this kind of trust. Watch for this paper to appear in policy conversations well beyond NIST.









