Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic published two cryptanalysis results — a working end-to-end key-recovery attack against HAWK-256 and a 200-to-800-fold speedup of an existing meet-in-the-middle attack on seven-round AES-128 — alongside technical papers and reproducibility code.
- HAWK-256 key-recovery work factor drops from an estimated 2^64 to 2^38 per Anthropic; the released implementation runs in roughly 3 hours 42 minutes on a 96-core server, exploiting an automorphism in the scheme's lattice that prior work had left unused.
- HAWK-512 and HAWK-1024, the actual NIST security-level parameter sets, see gate-count estimates revised from 2^150 to 2^108 and 2^288 to 2^182 respectively — still exponential and still impractical to attack.
- Seven-round AES-128 result removes a 256-way guessing step from a prior attack via a novel invariant fingerprint Anthropic calls the Möbius Bridge, but still requires roughly 2^105 chosen plaintexts encrypted under a fixed, unknown key.
- Claude Mythos Preview reportedly conducted both research efforts largely on its own: the HAWK result over ~60 hours in a multi-agent setup at ~$100,000 in API cost, and the AES breakthrough after about three days and roughly one billion output tokens.
- Human verification was the visible bottleneck — Anthropic says two researchers spent 'several hundred hours' and 'nearly a month' reaching confidence in the Möbius Bridge claim, and that the model initially refused to engage on AES, insisting the cipher was already optimal.
- NIST listed HAWK as a third-round candidate as of July 29, 2026, with no public response yet to the lower gate-count estimates; the disclosures follow the July 20 release of CryptAnalysisBench, a 191-task benchmark co-developed by ETH Zurich, Anthropic, the University of Haifa, TU Berlin, and Tel Aviv University.
Why it matters: **Anthropic** delivered a working HAWK-256 key-recovery that drops the estimated work factor from 2^64 to 2^38, alongside a 200-to-800-fold AES-128 speedup. Neither touches deployed systems, but NIST's post-quantum standardization process for HAWK now faces a concrete question about revising published security estimates for HAWK-512 and HAWK-1024.


