Anthropic's Claude Mythos Uncovers New Weaknesses in Encryption Algorithms
Anthropic researchers used Claude Mythos Preview to discover new weaknesses in two cryptographic methods, including one being considered by the National Institute of Standards and Technology (NIST) for traditional and quantum computing.
The company emphasized that neither flaw affects software currently in use, but the findings represent a substantial research advancement. One of the weaknesses was found in HAWK, a digital signature scheme under review by the NIST as part of a search for encryption methods that could survive attacks from quantum computers.
HAWK Weakness: A Mathematical Shortcut
Working with a human researcher, the AI system found a mathematical shortcut, known as a nontrivial automorphism, in the lattice structure underpinning HAWK's security. The discovered weakness cuts HAWK's effective key strength in half, meaning key sizes would need to double to maintain the same level of security.
Anthropic noted that this change would erase much of what made HAWK an appealing candidate in the first place. Ellen Boehm, senior vice president of strategy and AI innovation at Keyfactor, said that research like Anthropic's proves the NIST PQC evaluation process is working and elevates the importance for organizations to have visibility into their cryptographic systems.
AES Weakness: The Möbius Bridge
The other flaw was found in a weakened version of the Advanced Encryption Standard (AES), the cipher NIST adopted in 2001 and the most widely used method for scrambling data in transit. Working largely on its own, Mythos invented a mathematical shortcut dubbed the Möbius Bridge.
This discovery made the strongest known theoretical attack against seven-round AES 200 to 800 times faster. However, the attack is purely theoretical and requires an impossible amount of target data. Real-world systems remain completely safe, as the attack cannot touch the full 10-round encryption protecting everyday software.
Implications and Future Directions
Anthropic followed standard disclosure practices, notifying HAWK's designers in June and coordinating public release with a NIST mailing list. The company also worked with researchers at ETH Zurich, Tel Aviv University, and the University of Haifa to build a shared testing tool, called CryptanalysisBench.
The findings come as frontier AI models are being deployed by cybersecurity researchers to find vulnerabilities in software. Anthropic expects the same AI capabilities to eventually be applied to systems already in wide use, raising questions about how researchers, companies, and governments should respond if a language model uncovers a flaw in a cryptographic system that protects critical infrastructure.
Boehm emphasized that enterprises should not rest on their laurels with any facet of their security apparatus, as AI is becoming a powerful tool for software quality assurance, code development, and cryptographic analysis.
AI is becoming a powerful tool for many things, including software quality assurance, code development, and in this case cryptographic analysis. As AI tools become more widely and continuously used, it just elevates the need for enterprises to treat their trust infrastructure in an ongoing, operational manner versus thinking of it as a static environment that only changes every few years as new cryptographic algorithms are released.
Source: CyberScoop