Anthropic says its Mythos model found vulnerabilities in cryptographic algorithms that secure the internet
Anthropic's Claude Mythos Preview AI model discovered mathematical weaknesses in cryptographic algorithms, including a reduced version of AES and the post-quantum signature scheme HAWK. The model developed two attacks independently in a multi-agent system, with one attack on HAWK found in 60 hours for approximately $100,000 in API costs. While neither finding affects current systems (HAWK is still a NIST candidate and the AES attack applies to a modified 7-round version), this demonstrates AI's
Analysis
TL;DR
- Anthropic's Claude Mythos Preview AI model discovered mathematical weaknesses in cryptographic algorithms, including a reduced version of AES and the post-quantum signature scheme HAWK.
- The model developed two attacks independently in a multi-agent system, with one attack on HAWK found in 60 hours for approximately $100,000 in API costs.
- While neither finding affects current systems (HAWK is still a NIST candidate and the AES attack applies to a modified 7-round version), this demonstrates AI's potential to challenge core internet security assumptions.
- Human researchers provided minimal prompting and project management, while primarily verifying results after the AI generated hypotheses through experiments.
- Anthropic coordinated disclosure with relevant parties and created a new benchmark called CryptanalysisBench to evaluate language models' cryptanalytic abilities.
Why It Matters
This development represents a significant milestone in AI's capability to perform complex mathematical reasoning that traditionally requires specialized human expertise. For cybersecurity professionals and AI researchers, it highlights both the potential risks of advanced AI systems breaking encryption standards and opportunities for using AI to proactively identify vulnerabilities before malicious actors exploit them. The findings underscore the need for continued collaboration between AI developers and cryptographers as these technologies advance.
Technical Details
- Claude Mythos Preview worked semi-autonomously in a multi-agent system where one agent initially dismissed an approach as infeasible while another successfully exploited it
- For HAWK, the attack exploited a previously undetected symmetry in the mathematical lattice structure that underpins the scheme's security
- The AES attack used a novel "Möbius Bridge" fingerprinting method that improved upon previous attacks by factors of 200-800 by removing one required guess from attackers
- The model generated several hundred million tokens over three days with only three substantive human prompts during the AES investigation
- Researchers who weren't cryptography experts spent hundreds of hours verifying the AI-generated findings
- Anthropic collaborated with ETH Zurich, Tel Aviv University, and University of Haifa to develop CryptanalysisBench for systematic evaluation of language models' cryptanalytic capabilities
Industry Insight
The rapid discovery of cryptographic weaknesses by AI suggests that security protocols may need more frequent automated auditing than traditional manual review processes allow. Organizations should consider integrating AI-assisted cryptanalysis into their security testing frameworks while maintaining rigorous human verification processes. As AI capabilities continue advancing, we can expect increasingly sophisticated automated vulnerability discovery that will necessitate proactive rather than reactive approaches to cryptographic standardization and implementation.
Disclaimer: The above content is generated by AI and is for reference only.