Modelwire
Subscribe

Anthropic's Mythos finds new cryptographic weaknesses in 60 hours

Illustration accompanying: Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet

Anthropic's Mythos model identified previously undetected flaws in post-quantum cryptographic schemes, including an improved attack on HAWK that human researchers had validated over two years. The breakthrough cost roughly $100,000 in API calls and took 60 hours, signaling that frontier AI systems may outpace traditional security review cycles. While current deployed systems remain unaffected, the result underscores a structural vulnerability in how the security community validates cryptographic primitives against machine-driven adversaries, raising questions about AI's role in both breaking and defending critical infrastructure.

Modelwire context

Explainer

The detail worth sitting with is the validation timeline: human cryptographers took two years to confirm the HAWK attack Mythos surfaced, which means the bottleneck in catching these flaws has never been mathematical difficulty alone. It has been the sheer labor cost of exhaustive adversarial review, and that cost just dropped by several orders of magnitude.

This is largely disconnected from recent activity in our archive, so some broader context is warranted. Post-quantum cryptography is not a future concern: NIST finalized its first post-quantum standards in 2024, and governments and financial institutions are actively migrating. The security community has operated on the assumption that cryptographic primitives, once peer-reviewed and standardized, are stable for years. A system that can find novel attack vectors at $100,000 per run challenges that assumption structurally, not just in this one instance. The relevant comparison class is not AI benchmarks but the economics of offensive security research.

Watch whether NIST or the HAWK specification authors issue formal guidance or a revised security parameter recommendation within the next 90 days. If they do not respond publicly, that signals either the flaw is narrower than reported or the standards process has no clear protocol for AI-sourced vulnerability disclosures.

This analysis is generated by Modelwire’s editorial layer from our archive and the summary above. It is not a substitute for the original reporting. How we write it.

MentionsAnthropic · Claude Mythos · HAWK · The Decoder

MW

Modelwire Editorial

This synthesis and analysis was prepared by the Modelwire editorial team. We use advanced language models to read, ground, and connect the day’s most significant AI developments, providing original strategic context that helps practitioners and leaders stay ahead of the frontier.

Modelwire summarizes, we don’t republish. The Decoder originally reported this story as Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet”. The full content lives on the-decoder.com. If you’re a publisher and want a different summarization policy for your work, see our takedown page.

Anthropic's Mythos finds new cryptographic weaknesses in 60 hours · Modelwire