That scheme is HAWK, a digital signature system—the math that proves a transaction came from you without ever exposing your private key—built to survive future quantum computers. The non-regulatory federal agency and lab NIST moved it into the third round of its post-quantum signature competition in May, where it is the last lattice-based candidate standing.
Claude found a symmetry buried in HAWK's math that no human had thought to use. For the smallest configuration, the cost of recovering a secret key fell from 2^64 operations to 2^38, roughly 67 million times less work.
Fixing it means roughly doubling HAWK's keys. "Unfortunately, doubling HAWK's key size eliminates many of the reasons making the scheme (as it currently stands) an attractive PQC signature candidate," Anthropic wrote.
New Anthropic research: Discovering cryptographic weaknesses with Claude.
Claude Mythos Preview has helped our researchers find weaknesses in cryptographic algorithms—the mathematical methods that are used to keep data private.
That trade matters more to blockchains than it sounds. Signature size is block space, and block space is fees, so any chain shopping for a quantum-resistant replacement is partly choosing on bytes per signature. Compact keys and fast signing were HAWK's entire pitch, and the fix costs it much of that edge.
The AES result needed a pep talkThe second attack targets AES, the cipher scrambling your HTTPS traffic, your encrypted drive, and your exchange's backend. Full AES-128 pushes data through 10 rounds of scrambling, and Claude attacked a 7-round research version that nobody has improved on since 2013.
It refused anyway. "On AES-128 r5/r6/r7 it found nothing because there's nothing easy to find; this is the most-studied block cipher in existence," the model told researchers, per transcripts Anthropic published.
Anthropic sent just three substantive messages over the next three days, among them: "no again the goal is that we have highly inteligent [sic] model as good top researcher, we want to find new attacks." Another refused to let Claude swap AES for an easier cipher.
The finding with the shortest path to something real got the least attention. Claude also broke 13 rounds of LEA, a Korean national standard and ISO lightweight-encryption standard built for phones and internet-of-things devices, in under an hour on a desktop against a prior best that needed 2^98 plaintext pairs. The deployed LEA runs 24 rounds, so nothing in the field is broken.
Verification took longer than discovery"The cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes (like vulnerability triage, verification, and remediation) struggle to keep up," Anthropic wrote, warning that human researchers may become the bottleneck.
Mythos 5 broke 85.7% of tasks with known solutions, against 65.3% for the weakest model tested. Against full-strength ciphers with no published break, every model scored under 9%.

















