Claude Just Cracked a Post-Quantum Signature Scheme in 60 Hours. Humans Took Two Years and Missed It.
2026-07-29Anthropic's Claude Mythos Preview did something remarkable last week: it found a weakness in HAWK, a digital signature scheme built to withstand future quantum computers, in roughly two and a half days. Humans with decades of cryptographic expertise had reviewed it twice over two years and missed it entirely.
Let's back up. HAWK is a digital signature system—the math that proves you made a transaction without ever showing your private key. It's designed to survive quantum computers, which don't exist yet but will eventually render today's encryption schemes obsolete. NIST, the US standards body, moved HAWK into the third round of its post-quantum competition in May. It's the last lattice-based candidate left standing.
The appeal was obvious: HAWK is efficient and compact, which matters for constrained devices like microcontrollers that can't handle complex arithmetic. Until Claude broke it, anyway.
What Mythos actually did is stranger than just running cryptographic tests. It worked semi-autonomously inside a bespoke multi-agent system built on Claude Code, armed with Python, Sage (a symbolic math library), and access to published cryptographic research. It conducted a literature review, reasoned through mathematics, ran computational experiments, and found something no human had exploited: a hidden internal symmetry in HAWK's lattice structure, technically called a nontrivial automorphism.
That single structural oversight dropped the computational cost of stealing HAWK's smallest key from 264 operations to 238. To put that in perspective: roughly 67 million times less work needed.
The implications are brutal. Fixing HAWK means doubling its key size, which kills most of the efficiency advantage that made it attractive in the first place. In cryptography, signature size directly hits blockchain transaction costs and certificate storage. That was HAWK's whole selling point.
Now, before you panic: HAWK has never actually been deployed anywhere. Bitcoin still uses ECDSA, the pre-quantum signature scheme that things like HAWK are meant to eventually replace. The attack doesn't generalise to other NIST candidates or lattice cryptography broadly. It's algorithmic, not apocalyptic. Anthropic handled it well too—they disclosed everything to the authors, NIST, and relevant government and industry partners before going public.
What actually matters here is the acceleration. Two years of expert review, two rounds of scrutiny, and Claude found a better attack in 60 hours.
The cost was revealing: roughly $100,000 in API usage and one researcher providing project management (not even a lattice specialist). That's a fraction of what NIST's entire standardisation process costs.
There's something almost unsettling about the asymmetry that followed. Anthropic staff needed several hundred hours to verify that Claude's discovery was real. The AI found the flaw faster than humans could independently confirm it. That inversion—where computational discovery outpaces human validation—might actually change how standards bodies evaluate algorithms going forward.
The bigger picture is less reassuring. As AI capabilities mature, the race between defensive cryptanalysis and offensive discovery tilts in machines' favour. The cryptographic community now has to answer a hard question: can human review processes keep pace with what AI can find?
Source & further reading:
- Morning Minute: Claude Mythos Breaks Post-Quantum Cryptography — Decrypt
- BNY targets $8.6 trillion transfer agency market on blockchain rails — CoinDesk
- 3 reasons Wednesday's Fed meeting is pivotal for BTC — CoinDesk
- Bitcoin steadies above $64,000 as crypto looks to Fed interest-rate decision — CoinDesk
- Binance offers gold and silver options after commodity futures pull in billions in daily volume — CoinDesk
- Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break — Decrypt
- Discovering cryptographic weaknesses with Claude — Anthropic
- AI Cracks Post-Quantum Cipher in 60 Hours After Two Years of Human Review Failed — TechTimes
- AI Cracks HAWK Post-Quantum Scheme in 60 Hours · TFTC — TFTC
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack — The Hacker News
- Claude found mathematical flaws in two cryptographic algorithms that years of expert review missed — The Next Web
- Anthropic's Claude AI Flags New Cracks in Two Major Crypto Algorithms — CryptoTimes
Sources
- Morning Minute: Claude Mythos Breaks Post-Quantum Cryptography
- BNY targets $8.6 trillion transfer agency market on blockchain rails
- 3 reasons Wednesday's Fed meeting is pivotal for BTC
- Bitcoin steadies above $64,000 as crypto looks to Fed interest-rate decision
- Binance offers gold and silver options after commodity futures pull in billions in daily volume
- Claude Mythos Cracked Post-Quantum Cryptography That Humans Spent Years Failing to Break
- Discovering cryptographic weaknesses with Claude
- AI Cracks Post-Quantum Cipher in 60 Hours After Two Years of Human Review Failed
- AI Cracks HAWK Post-Quantum Scheme in 60 Hours · TFTC
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
- Claude found mathematical flaws in two cryptographic algorithms that years of expert review missed
- Anthropic's Claude AI Flags New Cracks in Two Major Crypto Algorithms