What Happened
Cryptography · Language Models · AI Capability · Source Verification · Research BriefAnthropic's announcement of 28 Jul 2026 · record to 28 Aug 2026
Executive summary · one-page brief
Read the Papers, Not Just the Post
Anthropic says its unreleased Claude Mythos Preview model produced two genuine cryptanalytic results: an improved key-recovery attack on the HAWK post-quantum signature scheme, and a faster attack on 7-round AES-128. Both are published as full papers, and both are real. But each paper also states a second, less flattering number for the same result that Anthropic's own blog post does not carry — a gap an independent reviewer of both documents has already pointed out in public.
The two results, and a benchmark Neither threatens a deployed system
- 200–800×AES-128 (7 rounds) speed-up Anthropic's post quotes — at a still-impractical data cost
- 2.7bits — the same paper's own balanced-complexity gain over the 2013 baseline
- 2^108 / 2^182HAWK-512 / HAWK-1024 key-recovery cost in gates, down from 2^150 / 2^288 under the specification's own model
- 85.7%CryptanalysisBench Tier-1 score for the model behind both attacks — highest of five models tested
Standing Sorted by how well each claim is evidenced
| Standing | What happened | When |
|---|---|---|
| Confirmed | Anthropic publishes a blog post and two full technical papers describing results from an unreleased model, Claude Mythos Preview: an improved HAWK key-recovery attack, and a faster 7-round AES-128 attack. | 28 Jul 2026 |
| Confirmed | The HAWK paper (Straznickas & Weis) reduces key recovery to poly(n) calls to an SVP oracle in dimension n/2+1 via a previously unused lattice automorphism, cutting HAWK-512 / HAWK-1024's gate-count cost from 2^150 / 2^288 to at most 2^108 / 2^182 under the specification's own model, and recovers two HAWK-256 test keys end-to-end. | 25 Jul 2026 |
| Confirmed | The AES paper (Nasr & Carlini) removes one of nine guessed key bytes from a 2013 7-round AES-128 attack, bringing runtime at the same 2^105-plaintext data budget to between 2^89.3 and 2^91.4 — though the same paper's own balanced-complexity metric puts the actual gain at only 2.7 bits. | 28 Jul 2026 |
| Confirmed | CryptanalysisBench, a companion benchmark built with academics at ETH Zurich, Tel Aviv University, the University of Haifa and TU Berlin, scores Mythos 5 at 85.7% on 49 known-broken schemes and 8.9% on 142 full-strength schemes with no known break — the highest of five models tested on both. | 20/29 Jul 2026 |
| Confirmed but not verifiable here | NIST cryptographer Daniel Apon replies on the NIST pqc-forum mailing list within hours, saying the HAWK result checks out independently for him — as reported by one independent reviewer of the announcement. | 28 Jul 2026 |
Timeline
From a 2013 baseline to this month's record Dated events only
- 2013Derbez, Fouque & Jean publish the previous-best 7-round AES-128 attack: 2^105 chosen plaintexts, 2^99 time.
- 2022HAWK is first proposed and later enters NIST's post-quantum digital-signature standardization process.
- May 2026NIST advances HAWK — one of nine candidates, and the only lattice-based one — to the third round of that process.
- Jun 2026Anthropic notifies HAWK's authors of the Mythos Preview result ahead of publication.
- 20 Jul 2026CryptanalysisBench is first posted to arXiv.
- 28 Jul 2026Anthropic publishes its blog post and both technical papers; HAWK co-author Stephen Weis posts the announcement to the NIST pqc-forum mailing list the same day, and NIST cryptographer Daniel Apon reportedly replies within hours confirming the HAWK result independently.
- 29 Jul 2026Anthropic edits its blog post (“updated an academic affiliation”); a revised CryptanalysisBench (v2) is posted; an independent analysis of both papers is published on PostQuantum.com.
- 28 Aug 2026As of this date, the public record does not show whether NIST or HAWK's submitters have changed the scheme's parameters or its standing in the standardization process.
Anthropic's own post names neither a month for HAWK's advance to the third round nor who replied on the NIST mailing list; both details come from independent reporting on the announcement — The Hacker News and Marin Ivezic's review, respectively.
- 9candidates NIST advanced to the third round; HAWK is the only lattice-based one
- 2/2HAWK-256 reference-generated public keys the released code recovered end-to-end
The Argument
What Anthropic's post says The headline framing
Anthropic's post frames both results in their most striking terms. On HAWK, it says the attack “effectively cutting its key strength in half,” and states the expected work factor for the smaller HAWK-256 parameter set as falling from 2^64 to 2^38. On AES, it says Mythos improved the speed of the previous best attacks by “200-800×.” Both numbers are real and both trace to the underlying papers — the 2^38 and the 200-800× figures each match a number the papers themselves compute.
What the papers' own tables say A second, less flattering number
Neither paper stops at its headline number. The HAWK paper's own Table 1 — using the gate-count model the HAWK specification itself relies on — gives HAWK-256's spec-side figure as 2^74, not 2^64; the 2^62 figure the paper gives under a different model (Core-SVP) is the closest match, and the 2^64 pairing in Anthropic's post does not appear in the table at all. The AES paper is explicit that its 200-800× figure holds only the data requirement fixed at 2^105 — itself still impractical — and that under the standard balanced metric max(D,T,M), which weighs data, time and memory together, the true gain over the 2013 baseline is 2.7 bits (or 2.1 bits, without one of the paper's own fingerprint assumptions). The paper states this about its own result: “the overall complexity of our attack has not improved” under the fixed-data framing alone.
Headline against table, side by side Same result, two numbers
| Claim | Anthropic's post | The paper's own table |
|---|---|---|
| HAWK-256 work factor | 2^64 → 2^38 | 2^74 → 2^52 (gate model) / 2^62 → 2^38 (Core-SVP) |
| AES-128 (7 rounds) speed-up | 200–800× | 2.7 bits (2.1 without one fingerprint assumption), balanced metric max(D,T,M) |
| HAWK-512 / HAWK-1024 key strength | “cut in half” | 2^150 → 2^108 (42 bits) / 2^288 → 2^182 (106 bits) |
None of this makes Anthropic's post false. Marin Ivezic, an independent security consultant who reviewed both papers, reaches the same reading: “the blog is a summary; the paper is the citable source, and the secondary coverage has been copying the blog.” The two attacks are real, published, and reviewable; the number a reader remembers depends on which document they read.
What Others Add
Three outside readings Security press, an independent analyst, and the paper's own acknowledgements
The Hacker News
A Candidate Doing Its Job
- HAWK is the only lattice-based scheme among the nine NIST advanced to the third round in May 2026.
- Anthropic's released code recovers a 592-byte decoded key, not the original 96-byte secret seed, and works only against HAWK-256.
- A 2025 paper by van Gent & Pulles had already shown a hypothetical automorphism would open this attack path, but its own authors said it did not then threaten HAWK; Mythos found the missing automorphism.
PostQuantum.com
The Process Worked
- Marin Ivezic notes Anthropic notified HAWK's team in June, posted to the NIST forum the same day as publication, and got an independent same-day check from a NIST cryptographer — disclosure norms followed, as with SIKE's 2022 break of a different candidate.
- His guidance for security teams: leave standardized-algorithm roadmaps (ML-KEM, ML-DSA, SLH-DSA, Falcon) alone — none is affected — and instead inventory any proprietary or vendor-specific cryptography, which is the population these results actually bear on.
- He calls the verification bottleneck — not either specific break — the thing worth watching, and cites cryptographer Markku-Juhani Saarinen's forum proposal that AI-assisted cryptanalysis should always ship machine-checkable proofs or scaled-down demonstrations.
The AES paper's acknowledgements
Six Names, Comments Only
- Nasr & Carlini thank Orr Dunkelman, Patrick Derbez, Jérémy Jean, Eyal Ronen, Nathan Keller and Adi Shamir — and say only that they gave “comments on an early draft.”
- Three of the six — Shamir, Dunkelman and Keller — are named co-authors of the 2010 and 2020 papers this attack directly extends; two more, Derbez and Jean, co-authored the 2013 baseline it improves on.
- The acknowledgement names no endorsement, no review, and no verification — only comments on a draft, and nothing further is claimed on their behalf.
The verification bottleneck The papers' own authors raise it
Nasr & Carlini describe the core AES idea as taking “tens of hours” of model time against “hundreds of hours” of their own validation, and call the resulting arrangement — humans mainly checking a model's output rather than producing it — something that “feels uncomfortable.” Ivezic treats that ratio, not either specific break, as “the thing I would put on a watch list,” describing a field that can now “discover” faster than it can review.
What stays true regardless The boundaries both sides agree on
HAWK is a candidate, not a deployed standard; the construction does not transfer to Falcon and does not touch ML-KEM, ML-DSA or SLH-DSA. Full 10-round AES-128 is untouched — the attack targets 7 rounds and still needs an impractical 2^105 chosen plaintexts. And CryptanalysisBench's own authors caution that because every Tier-1 scheme already has a published break, a model's “genuine”-looking win “does not by itself establish independent rediscovery” over recall of a known attack — roughly 78% of wins across all five tested models were judged genuine by the paper's own trace analysis, a proportion nearly identical across models rather than a Mythos-specific figure.
Conclusion
So what Real advances, read at the right resolution
What's solid
Two published, reviewable cryptanalytic advances against a not-yet-deployed post-quantum candidate and a reduced-round cipher already impractical at full strength, plus a benchmark on which the same model leads four rivals. No production system needs to change.
What's overstated
The two figures a reader is likeliest to remember — HAWK-256's “2^64 to 2^38” and AES's “200-800×” — are each the most favourable framing available, and each paper states a second, smaller number for the same result that its own announcement does not carry.
What's still open
Whether a model that discovers this fast can be verified this fast is a question the papers' own authors raise about themselves and do not answer. Whether NIST or HAWK's submitters respond by changing the scheme is, as of 28 Aug 2026, not yet shown in the public record either way.
- Watch whether NIST or HAWK's submitters respond — a parameter change, a withdrawal, or silence through the next standardization update would each say something different.
- Watch whether CryptanalysisBench's Tier-1 lead for Mythos-class models holds at longer time budgets — the paper's own 16-hour run already found most of that gain came from finishing attacks already found, not from new capability.
- Watch whether machine-checkable proofs or scaled-down demonstrations — Saarinen's proposal — become standard practice for AI-assisted cryptanalytic claims generally.
- Watch for any of the six cryptographers thanked in the AES paper's acknowledgements publishing their own assessment of the result, rather than the unquoted “comments” the paper itself reports.