Inboxsmith

AI news videos

Claude Found Real Flaws In Two Cryptographic Algorithms

Anthropic says Claude Mythos Preview has found mathematical flaws in cryptographic algorithms themselves, not just mistakes in how programmers implemented them. The first result is an improved key recovery attack on HAWK, a post-quantum digital signature scheme that is one of the remaining third-round candidates in NIST's call for additional signatures. HAWK had survived two rounds of expert human review over two years, but Claude found a previously unexploited symmetry in the underlying lattice, called a nontrivial automorphism, that effectively cuts the scheme's key strength in half. Anthropic says the work took about 60 hours. The expected cost of a full key recovery attack against the small HAWK-256 parameter was thought to be 2^64 and was demonstrated to be 2^38. The attack is still exponential, not a polynomial-time break, it is specific to HAWK, and it does not affect other NIST post-quantum candidates or lattice cryptography in general. The second result targets AES-128 reduced from ten rounds to seven, a weakened variant that researchers study to measure how much safety margin the full cipher has. Claude developed a fingerprinting algorithm it called a Mobius Bridge that removes a 256-way guessing step from the previous best meet-in-the-middle attack, making it between 200 and 800 times faster. That attack assumes roughly 2^105 chosen plaintexts, so it is completely impractical. To be clear on the impact: neither result affects production systems and Anthropic says no production software will have to change. HAWK is only a candidate scheme and is not deployed, and the AES result does not break the full ten-round cipher used in the real world. Anthropic says each result cost roughly 100,000 dollars in API cost, that Claude worked mostly autonomously, and that human verification was the slow part, with two researchers spending nearly a month gaining confidence the AES method was correct.

Watch on YouTube

Transcript

Anthropic said today that Claude found real mathematical flaws inside cryptographic algorithms that human experts missed for years.

HAWK is a post quantum signature candidate at NIST, not deployed anywhere. It survived two years of expert review. Then Claude halved its effective key strength in sixty hours.

The AES result attacks seven of ten rounds, a weakened variant. A new fingerprint, Mobius Bridge, makes it two hundred to eight hundred times faster, yet still completely impractical.

No production software has to change, Anthropic says. Claude worked mostly autonomously for about one hundred thousand dollars in API cost. Verification took two researchers nearly a month.

Inboxsmith helps small businesses handle calls and messages so nothing gets missed. Please like and subscribe for more news.

Sources

Every claim in this video comes from the top ranking coverage of this topic. The claims and where each one came from:

We make Inboxsmith.

An AI receptionist that never misses a business call.

See how it works