
Anthropic says an internal model called Claude Mythos Preview has identified weaknesses in two cryptographic targets, including an improved attack on HAWK, a post-quantum signature candidate, and a new attack on a reduced version of AES-128. The company says neither result breaks systems used on the internet today, but the work is notable because it suggests frontier AI systems may be starting to contribute to advanced cryptanalysis rather than only assisting with coding, search, or document work.
The report, described by The Decoder based on Anthropic’s disclosure, centers on a semi-autonomous multi-agent setup in which the model reportedly did most of the technical exploration while humans handled project management, prompting, and verification. Anthropic says the HAWK result emerged in about 60 hours after years of prior human review by specialists, and that each project run cost roughly $100,000 in API usage. If those details hold up under broader scrutiny, the development matters well beyond one model release: it would imply AI systems are becoming capable of meaningful original work against difficult mathematical security problems.
According to The Decoder’s account of Anthropic’s findings, Claude Mythos Preview produced two separate results. The first was an improved attack on HAWK, one of the remaining candidates in a National Institute of Standards and Technology process for additional post-quantum signatures. Post-quantum cryptography is meant to remain secure even if large-scale quantum computers eventually become practical, so any new weakness in a candidate scheme is significant for standards work even if it does not affect deployed products.
Anthropic says the model discovered a previously unnoticed symmetry in the lattice structure underlying HAWK’s security. In the company’s telling, one agent in the system initially treated the approach as infeasible, while another found a way to exploit it. That detail matters because it frames the result less as a single-shot answer from a chatbot and more as an orchestrated research workflow using multiple model roles.
The second result concerns AES-128, but with an important limitation. Anthropic says the attack applies only to a reduced-round version using seven rounds rather than the ten rounds in full AES-128. AES remains the most widely used symmetric encryption standard in practice, so any mention of a “new AES attack” can sound more alarming than the evidence supports. Based on the available reporting, this is not a break of full AES as used in common internet and enterprise systems.
For that reduced-round target, Anthropic says Claude Mythos developed a new fingerprinting approach it calls “Möbius Bridge.” The company claims the method improves on prior attacks by a factor of 200 to 800 by eliminating one of the attacker’s guesses. That is a technical performance claim from the vendor side, not an independently validated industry benchmark in the evidence provided here.
The HAWK finding appears to be the more consequential part of the story because it touches an active standards pipeline rather than a deliberately weakened version of an established cipher. The Decoder reports that human experts had reviewed HAWK for more than two years before Claude Mythos Preview found a stronger attack in roughly 60 hours. Even with the caveat that the model was embedded in a structured workflow and later checked by humans, that comparison is the core reason the news is getting attention.
HAWK is not a deployed internet standard today. It is a candidate under review by National Institute of Standards and Technology, and that distinction sharply limits the immediate operational risk. But for teams building cryptographic tools, secure hardware, or long-lived regulated systems, the episode is a reminder that the evaluation process for post-quantum cryptography may speed up and become less predictable as AI systems improve.
It also introduces a more practical question for researchers and standards bodies: if models can find real weaknesses in candidate schemes at nontrivial but manageable cost, then the bar for public cryptanalysis may shift. That does not automatically mean better attacks on widely deployed algorithms are imminent. It does mean future rounds of review for post-quantum cryptography could see more automated adversarial testing than traditional peer review alone.
A key issue in assessing this announcement is how much of the work should be credited to Claude Mythos versus the surrounding system and human operators. Anthropic’s description, as reported by The Decoder, says humans were mostly responsible for project management, light prompting, and verification. In the HAWK project, the company says the lead human researcher had a theoretical computer science background but was not an expert in lattice-based cryptography.
For the reduced-round AES work, Anthropic says a researcher created a scaffold that let the model form hypotheses and run experiments. The company also says the model initially resisted the task, arguing that further improvements were unlikely, before it was pushed to pursue more original lines of inquiry. Over about three days, the run reportedly consumed around 1 billion tokens and required only a few substantive follow-up prompts.
Those details cut two ways. On one hand, they support Anthropic’s claim that the system did more than autocomplete known ideas. On the other, they show that this was not a simple out-of-the-box chat session. It involved a purpose-built research setup, heavy token usage, and extensive post-run checking. For builders working on AI agents, the lesson may be less “the model solved cryptography alone” and more “carefully structured multi-step systems can sometimes extract frontier-level work from a model in narrow domains.”
The strongest claims in this story are vendor-reported through Anthropic and relayed by The Decoder. The article says human researchers spent several hundred hours verifying the outputs and that Anthropic shared the findings in advance with the U.S. government, industry partners, and the authors of HAWK. That disclosure process is a positive sign, but it is not the same as broad public validation.
The evidence provided here does not include a peer-reviewed paper, independent replication, or responses from National Institute of Standards and Technology, the HAWK authors, or external cryptographers. It also does not establish whether the improved HAWK attack materially changes the candidate’s standing in the standards process. Those are important unknowns.
Anthropic also says Claude Mythos Preview is not publicly available. That limits outside testing of the company’s claims for now. Alongside the model work, Anthropic says it collaborated with ETH Zurich, Tel Aviv University, and the University of Haifa on a benchmark called CryptanalysisBench to evaluate language models on cryptanalysis tasks. Benchmarks can help the field compare systems more systematically, but they are not substitutes for independent review of claimed breaks or attacks.
For AI builders, this story points to a class of use cases that looks very different from enterprise copilots or consumer chatbots. Cryptanalysis is expensive, narrow, and verification-heavy. But it rewards persistent search over vast hypothesis spaces, which is exactly where agentic systems may improve quickly. Companies developing AI agents for research workflows will likely study this case closely, especially the combination of orchestration, experiment loops, and lightweight human steering.
For enterprise AI buyers, the immediate takeaway is not that internet encryption has become unsafe. Anthropic explicitly says the results do not affect systems in use today, and the available evidence supports that caution. The more relevant implication is organizational: security teams may need to assume that both defenders and attackers will get access to stronger automated analysis over time. That could affect vulnerability research, protocol review, red-teaming budgets, and procurement assumptions around “battle-tested” cryptographic components.
There is also a market signal here for enterprise AI more broadly. If Anthropic can show that frontier models contribute real value in difficult scientific or mathematical domains, it strengthens the case that model vendors are competing not only on chat quality but on specialized reasoning. That would put pressure on rivals to demonstrate comparable depth in areas such as formal verification, secure code analysis, and research automation.
The first follow-up signal is external validation. Watch for commentary from cryptographers, the HAWK authors, and National Institute of Standards and Technology on whether the reported HAWK weakness meaningfully alters the candidate’s prospects.
Second, look for technical publication. A public paper or detailed write-up on the HAWK and AES-128 results would let the broader research community test the claims and understand how much depended on the model versus the surrounding scaffold.
Third, CryptanalysisBench could become a useful reference point if multiple labs adopt it. If other frontier models perform similarly on CryptanalysisBench, the story shifts from a one-off Anthropic claim to a broader capability trend.
Finally, availability matters. Claude Mythos Preview remains unreleased, according to the reporting. Without wider access, the market cannot easily judge reproducibility, cost efficiency, or whether this capability generalizes beyond a few carefully selected problems.
Anthropic’s announcement is most important as a signal about workflow design, not just model intelligence. The notable element is the pairing of Claude Mythos with a managed multi-agent process, experimental scaffolding, and long verification cycles. That is closer to how high-value enterprise AI systems will likely operate in practice than the usual chatbot demo.
At the same time, this story needs more independent confirmation before it should reshape security planning. For now, builders should read it as evidence that frontier AI may start to matter in expert research domains like post-quantum cryptography, while enterprises should treat it as an early warning about the pace of automated security analysis rather than as proof that deployed encryption standards are at risk.
Anthropic says Claude Mythos found flaws in HAWK and reduced-round AES, signaling AI may accelerate cryptanalysis without threatening current systems.