# Claude finds new attacks on reduced-round AES and post-quantum HAWK scheme

> Anthropic's Claude Mythos AI model found new cryptanalytic attacks on several ciphers

*Anthropic said its Claude Mythos Preview model uncovered cryptographic weaknesses that took human researchers weeks to verify*

By Behzad Hosseini · WireRead
Canonical: https://wireread.com/news/claude-finds-new-attacks-on-reduced-round-aes-and-post-quantum-hawk-scheme

Anthropic published research on 28 July 2026 describing how its Claude Mythos Preview model discovered new attacks on several cryptographic schemes, including a post-quantum signature standard and reduced-round versions of AES. Anthropic said the findings show an AI system producing original results in cryptanalysis, one of the most demanding fields of mathematics and security.

The model cut the effective key size of HAWK, a post-quantum digital signature scheme, by 50%, according to Anthropic. That result took about 60 hours of work and roughly $100,000 in API cost, and the HAWK authors were notified in June, the company said.

Against AES reduced to 7 rounds, not the full cipher, the model produced an attack 200 to 800 times faster than the best previously known method. That work took about 3 days of autonomous effort and consumed roughly 1 billion output tokens, at a similar API cost of about $100,000, Anthropic said.

The model also found a practical attack on LEA reduced to 13 rounds, requiring fewer than 2^30 plaintexts and running in under an hour, and achieved full key recovery on Serpent-128 reduced to 6 rounds, according to the notes published by Anthropic. Attempts against Salsa20, Poseidon and SHA-1 produced only small improvements, under 10 times faster than prior methods.

Anthropic said human researchers had to validate the results before publication. For the AES finding, two researchers spent nearly a month, several hundred hours, learning cryptography as they worked to confirm the result was correct. The HAWK result was checked by one researcher with a background in theoretical computer science.

Reduced-round variants of ciphers are the standard way cryptographers measure a cipher's safety margin, and Anthropic said full-strength AES remains unbroken. Disclosure of the findings was coordinated with the US National Institute of Standards and Technology, the US government and industry partners, according to the company.

"Without secure cryptographic systems like these, your email, online banking, and other internet use would be open to cybercriminals, who could intercept or modify your communications," Anthropic said. Further details are in [Anthropic's research post](https://www.anthropic.com/research/discovering-cryptographic-weaknesses).

## Key takeaways

- Claude Mythos cut HAWK's effective key size by 50% after about 60 hours and $100,000 in API cost
- Seven-round AES attack ran 200 to 800 times faster than the best prior known method
- Disclosure was coordinated with NIST, the US government and industry partners

## Sources

- [Discovering cryptographic weaknesses with Claude](https://www.anthropic.com/research/discovering-cryptographic-weaknesses) — Anthropic, 2026-07-28
