TL;DRClaude Mythos found mathematical weaknesses in HAWK (halving key strength) and reduced-round AES (200-800x faster attack). Both discovered mostly autonomously. No production systems affected. Each cost ~$100K.
Anthropic announced on Monday that Claude Mythos Preview has discovered mathematical weaknesses in two cryptographic algorithms. The first substantially weakens HAWK, a post-quantum digital signature scheme under review by NIST, by cutting its effective key strength in half. The second improves the best-known attack on seven-round AES, the most widely used symmetric cipher, by 200-800x. Neither result affects production systems. HAWK is not deployed, and the AES attack targets a reduced variant, not the full cipher.
The distinction from Anthropic’s earlier cybersecurity work is critical. Claude had previously found vulnerabilities in cryptographic libraries, meaning bugs in how programmers implemented algorithms. These new results are flaws in the mathematics of the algorithms themselves, discovered after years of expert human review failed to find them. HAWK survived two rounds of NIST review over two years. Mythos found the weakness in 60 hours of semi-autonomous work, with one researcher providing project management direction rather than technical guidance. The AES result was discovered almost entirely autonomously after Claude initially refused to try, claiming improvement was impossible. A researcher sent three encouraging prompts over three days. Claude produced one billion output tokens and invented a technique it named the “Möbius Bridge.”










