Claude Broke Post-Quantum Crypto in 60 Hours. Two Years of Humans Missed It.
2026-07-29Anthropic's Claude Mythos Preview cracked a critical flaw in HAWK, a post-quantum digital signature scheme being evaluated by NIST. The model did it in 60 hours. Cryptographers worldwide had been probing this thing since its submission and didn't find a thing through two full rounds of review.
Here's the actual damage. HAWK-256's smallest configuration was supposed to resist a full key recovery attack costing 2^64 operations. Claude showed it actually costs 2^38. That's not a rounding error. That's the difference between computationally impossible and very expensive.
The attack exploits a previously unconfirmed symmetry—a nontrivial automorphism in HAWK's lattice structure. Everyone knew if such a symmetry existed, it would break the scheme faster. Nobody had actually found one. Claude did. And it did it by deploying the attack itself: on a 96-core server, the released code recovers the HAWK-256 signing material in approximately three hours and 42 minutes.
This creates a mess for NIST. HAWK was a lattice-based candidate—the only one among nine advanced to the third round of NIST's post-quantum digital signature process in May 2026. The scheme's entire appeal was compact keys and fast signing. That matters for blockchains. Signature size is block space. Block space is fees. Any chain hunting for a quantum-resistant replacement chooses partly on bytes per signature. HAWK's selling point was it wouldn't bloat your blocks. Fixing this vulnerability requires expanding key sizes. It costs HAWK its main edge.
But here's what doesn't happen. The attack beats exponential time—it's faster than anything known before. It doesn't run in polynomial time. It's specific to HAWK. Other NIST post-quantum signature candidates are untouched. General lattice-based cryptography is fine. And this hasn't deployed anywhere. Bitcoin still runs on ECDSA. That pre-quantum signature scheme has years before it faces real threat.
Claude moved beyond HAWK. It invented a new fingerprinting technique for AES—the Möbius Bridge—that eliminates a computationally expensive guessing step in the existing best attack. It sped up an attack on a 7-round version of AES by 200 to 800 times, beating a record set by humans in 2013. Full-strength AES—protecting HTTPS, encrypted drives, exchange backends—stays unbroken. But seven of AES-128's ten rounds fell harder than before.
The costs tell you something about scaling this. Anthropic said Mythos Preview developed and verified the result over approximately 60 hours in a multi-agent environment. API costs ran about $100,000. Then reality hit: Anthropic researchers spent several hundred hours learning enough cryptography to confirm the attack actually worked. An AI found the flaw faster than humans could verify it.
Anthropic disclosed the attack to HAWK's authors in June. Full public disclosure hit the NIST mailing list today alongside the research release. The HAWK team helped verify before it went public. That's responsible process. A flaw caught before deployment gets fixed. One found after forces emergency migrations across critical infrastructure.
The cybersecurity community is now confronting a harder fact. Language models discover so many bugs the standard human processes—triage, verification, remediation—can't keep pace. Claude cracked this in less than three days. Humans needed hundreds of hours to validate it. As NIST evaluates the nine remaining candidates, that asymmetry will reshape how we think about cryptographic review and how long standardization takes.
Source & further reading:
- Ondo shifts from layer-1 blockchain plan to offchain execution network — Cointelegraph
- Live updates: Bitcoin clears $64,000 in Asia hours ahead of Fed decision — CoinDesk
- Company behind AI trade that caused $60 million crypto liquidations to cover all losses — CoinDesk
- Citadel bets on a Fed rate hike Wednesday as bitcoin analysts call a hold. Someone will be wrong. — CoinDesk
- Bitcoin rises toward $64,000 as Korea's record chip crash leaves crypto untouched — CoinDesk
Sources
- Ondo shifts from layer-1 blockchain plan to offchain execution network
- Live updates: Bitcoin clears $64,000 in Asia hours ahead of Fed decision
- Company behind AI trade that caused $60 million crypto liquidations to cover all losses
- Citadel bets on a Fed rate hike Wednesday as bitcoin analysts call a hold. Someone will be wrong.
- Bitcoin rises toward $64,000 as Korea's record chip crash leaves crypto untouched