AI TechnologyAnthropicJul 28, 2026 21:21 UTC

Anthropic's AI Discovers Vulnerability in Cryptographic Technology

Anthropic announced that its AI model 'Claude Mythos Preview' discovered a more effective attack method against the post-quantum cryptographic algorithm 'HAWK'. While human experts had spent over two years verifying the security of the algorithm, the AI identified the vulnerability in approximately 60 hours with an API cost of around $100,000. Although there is reportedly no direct impact on currently operational systems, this case is notable as it demonstrates that AI can participate in assessing the security of cryptographic technologies that form the foundation of internet security.

Anthropic's AI Discovers Vulnerability in Cryptographic Technology

The AI model 'Claude Mythos Preview' developed by Anthropic discovered a vulnerability in the cryptographic algorithm that supports internet security. The target algorithm is called 'HAWK,' a next-generation signature scheme designed to withstand attacks from quantum computers. Despite human experts having spent over two years verifying its security, the AI found a more effective attack method in approximately 60 hours.

'Post-quantum cryptography' like HAWK is a collective term for cryptographic technologies being developed to prevent decryption by future quantum computers. Current cryptography widely used on the internet is theoretically susceptible to being broken if quantum computers become practical, and research institutions and standards organizations worldwide are accelerating efforts to prepare successor technologies. HAWK itself had undergone long-term review by the expert community as one of the candidate algorithms.

The cost incurred for this analysis was approximately $100,000 in API usage fees. A problem that a human expert team had overlooked over two years was discovered by AI in a matter of tens of thousands of dollars and 60 hours. Anthropic explained that this discovery has no direct impact on currently operational systems.

However, the significance of this result is not insignificant. The security assessment of cryptographic technology has been a field that has historically relied on highly specialized human expertise. This case demonstrates that AI can play a new role against this premise. Based on this discovery, Anthropic suggests that AI could potentially call into question the underlying assumptions of internet security.

On the other hand, this type of capability has a dual-use nature—it can be used for both attack and defense. The task of finding cryptographic vulnerabilities has traditionally been conducted as a 'red team activity' to enhance security. If AI can perform this task with lower cost and higher speed, it could lead to discussions about revising not only the approach to security research but the entire process of reviewing and developing cryptographic standards.

What is known at this point is that the attack method against the specific algorithm HAWK has been improved, and the impact on other post-quantum cryptographic algorithms cannot be confirmed from this report. Furthermore, the specific details and severity of the discovered vulnerability have not yet been clearly revealed. Going forward, attention will focus on verification and response efforts by the cryptographic research community.

The acceleration of security research by AI has the potential to bring technical benefits, while simultaneously carrying the structural risk that the same capabilities could be misused for malicious purposes. This case raises anew the question of how AI development companies will responsibly disclose the capabilities of their models and how the industry as a whole should respond.

#Anthropic#Claude#Cryptography#CyberSecurity#PostQuantumCryptography#AISecurity#GenerativeAI
AI issue Staff

This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.

Comments

Log in to comment