Skip to main content
SuggestedTech
Back to all news

Anthropic

What Anthropic's Claude AES and HAWK cryptography research means for you

Anthropic said its Claude Mythos model found faster attacks on weakened versions of AES and halved the effective key size of a post-quantum signature scheme.

By , Editor-in-Chief · SuggestedTechVerified July 2026

The answer

Claude found new weaknesses in scaled-down versions of encryption schemes, not full AES.

Anthropic has published research showing its Claude Mythos Preview model discovered new attacks on several cryptographic schemes — the mathematical systems that keep your data private online. The most notable results involve a post-quantum signature scheme called HAWK and a weakened version of AES, the encryption standard used to protect everyday internet traffic.

What happened

According to Anthropic's research, published on 28 July 2026, Claude Mythos found that the effective key size of HAWK — a digital signature scheme designed to resist attacks from future quantum computers — could be cut in half. That work took the model around 60 hours and roughly $100,000 in computing costs. Anthropic notified HAWK's creators in June.

Separately, Claude found an attack on AES reduced to 7 rounds that was 200 to 800 times faster than the best attack previously known. AES normally runs through more rounds of scrambling than this; cryptographers study these "reduced-round" versions deliberately, as a way of measuring how much safety margin a cipher has before it becomes vulnerable. Full-strength AES was not broken. This result took about 3 days of autonomous work, 1 billion output tokens, and roughly $100,000 in costs.

Claude also found a practical attack on a 13-round version of the cipher LEA, needing fewer than 2^30 sample messages and running in under an hour, and achieved full key recovery on a 6-round version of Serpent-128. Attempts against Salsa20, Poseidon and SHA-1 produced only minor improvements.

Because AI-generated results can contain errors, Anthropic had humans check the work. Two researchers spent nearly a month — several hundred hours, during which they had to learn relevant cryptography — verifying the AES result. The HAWK finding was checked by one researcher with a background in theoretical computer science. Anthropic coordinated disclosure with NIST, the US government, and industry partners.

Anthropic said: "Without secure cryptographic systems like these, your email, online banking, and other internet use would be open to cybercriminals, who could intercept or modify your communications."

What it means for you

Nothing changes for your day-to-day use of email, banking apps or websites right now. The attacks target scaled-down or specialised versions of cryptographic schemes, not the full-strength systems that currently protect your data. Full AES remains secure.

The bigger signal is about where AI capability is heading. Cryptography is one of the most demanding fields of mathematics, and Anthropic's notes describe this as AI producing original results in it — something worth watching if you rely on encryption for privacy or security, which almost everyone online does.

What happens next

Anthropic coordinated its disclosure with NIST, the US government and industry partners before publishing, the standard process for reporting cryptographic weaknesses responsibly. The notes do not say what changes, if any, HAWK's designers or other affected projects plan to make as a result.

Sources

← All news