Anthropic says Claude found new weaknesses in cryptographic algorithms

Anthropic says Claude found new weaknesses in cryptographic algorithms

Anthropic found that Claude Mythos discovered new ways to attack cryptographic algorithms, though the findings do not affect systems in use today.

Anthropic said Claude Mythos Preview discovered improved attacks against two cryptographic algorithms, showing that frontier AI models can identify mathematical weaknesses that escaped years of human review.

The first finding significantly weakens HAWK, a post quantum digital signature scheme being evaluated by the National Institute of Standards and Technology. The second improves an attack against a reduced version of the Advanced Encryption Standard by between 200 and 800 times.

Neither result affects systems currently in use. HAWK has not been deployed, while the AES attack applies only to a seven round research version rather than the complete ten round AES 128 cipher.

Claude identified a previously unused mathematical symmetry in HAWK that enabled a faster key recovery attack and effectively cut the scheme’s key strength in half.

For the smallest HAWK 256 configuration, the estimated cost of recovering a key fell from 2 to the power of 64 operations to 2 to the power of 38.

The attack remains impractical against larger keys and does not affect other post quantum signature candidates. However, Anthropic said HAWK would need to double its proposed key sizes to maintain the intended security level, reducing its efficiency advantages.

Claude developed the attack in about 60 hours using a multi agent research system with access to mathematical software, published research, and computational tools.

Advertisement

A human researcher provided occasional guidance but lacked specialist knowledge of lattice based cryptography. Anthropic estimated that the work cost about $100,000 in API usage.

The second finding targeted seven round AES 128, a deliberately weakened version of the cipher used in real world systems.

Claude improved an existing meet in the middle attack with a fingerprinting method called the Möbius Bridge. The technique removed one required guess, reducing part of the workload by a factor of 256.

After accounting for the additional computing required, Anthropic estimated that the full attack was between 200 and 800 times faster than previous methods.

Claude discovered the central idea largely autonomously and generated about one billion output tokens while refining the approach.

Anthropic researchers then spent several hundred hours validating the result, substantially longer than the model took to discover it.

The company also disclosed preliminary findings involving other cryptographic algorithms.

Claude developed an attack against a reduced 13 round version of the Lightweight Encryption Algorithm that can recover a key in less than an hour on a modern desktop computer.

It also found a key recovery attack against six rounds of the 32 round Serpent 128 cipher and smaller improvements involving Salsa20, Poseidon, and SHA 1.

None of these findings compromise the complete versions used in production.

Anthropic partnered with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa to create CryptanalysisBench, a benchmark for measuring how well language models analyze cryptographic systems.

The company said it followed responsible disclosure procedures and consulted academic, government, and industry specialists before publishing the findings.

Anthropic said AI could help identify weaknesses before new cryptographic standards are deployed, but warned that future models may discover flaws with immediate consequences for real world security.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

Anthropic says Claude found new weaknesses in cryptographic algorithms

Anthropic says Claude found new weaknesses in cryptographic algorithms

Anthropic found that Claude Mythos discovered new ways to attack cryptographic algorithms, though the findings do not affect systems in use today.

Anthropic said Claude Mythos Preview discovered improved attacks against two cryptographic algorithms, showing that frontier AI models can identify mathematical weaknesses that escaped years of human review.

The first finding significantly weakens HAWK, a post quantum digital signature scheme being evaluated by the National Institute of Standards and Technology. The second improves an attack against a reduced version of the Advanced Encryption Standard by between 200 and 800 times.

Neither result affects systems currently in use. HAWK has not been deployed, while the AES attack applies only to a seven round research version rather than the complete ten round AES 128 cipher.

Claude identified a previously unused mathematical symmetry in HAWK that enabled a faster key recovery attack and effectively cut the scheme’s key strength in half.

For the smallest HAWK 256 configuration, the estimated cost of recovering a key fell from 2 to the power of 64 operations to 2 to the power of 38.

The attack remains impractical against larger keys and does not affect other post quantum signature candidates. However, Anthropic said HAWK would need to double its proposed key sizes to maintain the intended security level, reducing its efficiency advantages.

Claude developed the attack in about 60 hours using a multi agent research system with access to mathematical software, published research, and computational tools.

Advertisement

A human researcher provided occasional guidance but lacked specialist knowledge of lattice based cryptography. Anthropic estimated that the work cost about $100,000 in API usage.

The second finding targeted seven round AES 128, a deliberately weakened version of the cipher used in real world systems.

Claude improved an existing meet in the middle attack with a fingerprinting method called the Möbius Bridge. The technique removed one required guess, reducing part of the workload by a factor of 256.

After accounting for the additional computing required, Anthropic estimated that the full attack was between 200 and 800 times faster than previous methods.

Claude discovered the central idea largely autonomously and generated about one billion output tokens while refining the approach.

Anthropic researchers then spent several hundred hours validating the result, substantially longer than the model took to discover it.

The company also disclosed preliminary findings involving other cryptographic algorithms.

Claude developed an attack against a reduced 13 round version of the Lightweight Encryption Algorithm that can recover a key in less than an hour on a modern desktop computer.

It also found a key recovery attack against six rounds of the 32 round Serpent 128 cipher and smaller improvements involving Salsa20, Poseidon, and SHA 1.

None of these findings compromise the complete versions used in production.

Anthropic partnered with researchers from ETH Zurich, Tel Aviv University, and the University of Haifa to create CryptanalysisBench, a benchmark for measuring how well language models analyze cryptographic systems.

The company said it followed responsible disclosure procedures and consulted academic, government, and industry specialists before publishing the findings.

Anthropic said AI could help identify weaknesses before new cryptographic standards are deployed, but warned that future models may discover flaws with immediate consequences for real world security.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.