Anthropic said its Mythos AI security model found a weakness in the post-quantum digital signature candidate HAWK, prompting the algorithm’s withdrawal from NIST consideration after the system reportedly identified a new way to locate automorphisms that cut HAWK’s effective security roughly in half. The same research also improved a meet-in-the-middle attack on a deliberately weakened seven-round AES challenge, reducing the known-plaintext requirement from about 2^105 to 2^89, although both results were described as impractical against widely deployed production cryptography and focused on challenge systems or immature candidates rather than live enterprise deployments.
The developments come amid broader concern that AI is changing how cryptanalytic claims are validated, because multiple researchers may rely on the same models and inherit common failure modes while appearing independent. Recent examples cited in the debate include near-simultaneous July papers on unclonable encryption that both credited OpenAI’s GPT-5.6 Sol Ultra with core ideas, and AI-assisted reviews of a claimed polynomial-time algorithm for the Dihedral Coset Problem that disclosed model involvement unevenly; researchers are calling for clearer provenance, explicit verification-status reporting, and continued emphasis on crypto-agility rather than abrupt changes to post-quantum deployment plans based on early AI-assisted findings.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
Daniel Simon posted a claimed polynomial-time algorithm for the Dihedral Coset Problem. Because of possible implications for assumptions underlying ML-KEM, ML-DSA, and FN-DSA, the claim drew immediate scrutiny.
Review of Simon’s claim on the qcryptanalysis Discord server surfaced serious issues, including disputed points in Lemmas 3 and 4. Daniel Apon circulated “The Search for Simon,” arguing the proof strategy had no local repair, while Michael David Gardiner circulated an AI-assisted draft identifying a post-selection gap.
Pierre Botteron, Anne Broadbent, Eric Culf, Ion Nechita, Clément Pellegrini, and Denis Rochette published a closely related unclonable encryption scheme in Quantum. Later July arXiv papers positioned their own contributions relative to this result.
Prabhanjan Ananth and Amit Sahai posted “Unconditional Unclonable Encryption” on arXiv, and Seyoon Ragavan posted “Efficient Unclonable Encryption from Pauli Eigenstates” three hours and eighteen minutes later. Both papers credited OpenAI’s GPT-5.6 Sol Ultra with core ideas and traced their work to the same open problem raised earlier that month at a Simons Institute talk in Berkeley.
The International Association for Cryptologic Research adopted an AI-use policy applying at Crypto, Eurocrypt, and TCC. The policy bars listing generative AI tools as authors and requires disclosure appendices for substantial generated content.
Yilei Chen posted an update stating that Step 9 of his claimed LWE algorithm contained a bug he did not know how to fix. He thanked Hongxun Wu and Thomas Vidick for independently finding the flaw.
During the NIST PQC Standardization Conference, Yilei Chen posted a claimed polynomial-time quantum algorithm for Learning With Errors. The claim became a test case for how cryptanalytic results are independently reviewed.
Anthropic also said Mythos improved a meet-in-the-middle attack on a deliberately weakened seven-round AES instance, reducing the required known plaintext inputs from about 2^105 to 2^89. The article notes the attack remains impractical outside laboratory conditions and does not affect standard deployed AES.
After Anthropic announced its findings, HAWK’s developer confirmed that the post-quantum signature candidate was being withdrawn from consideration. HAWK had already passed two rounds of NIST evaluation and was in a third round of testing.
Anthropic reported that its Mythos AI security model discovered a previously unknown way to locate automorphisms relevant to attacks on HAWK, improving the best known attack after about 60 hours and roughly $100,000 in compute. The result reportedly cut HAWK’s effective key strength roughly in half.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcepostquantum.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.