Research · 3 min read

The Möbius Bridge: Claude Mythos Finds Cryptographic Weaknesses NIST Review Missed

Anthropic reports Claude Mythos improved attacks on the HAWK post-quantum signature candidate and reduced-round AES, releases CryptanalysisBench, and warns verification — not discovery — may become the bottleneck.

By Classy AI News · July 28, 2026

The Möbius Bridge: Claude Mythos Finds Cryptographic Weaknesses NIST Review Missed

On July 28, 2026, Anthropic's Frontier Red Team published results that move the conversation about language-model mathematics from Erdős problems and Jacobian conjectures into the infrastructure layer of the internet: cryptography itself.

Using Claude Mythos Preview, researchers reported improved attacks against HAWK — a third-round candidate in NIST's post-quantum digital signature competition — and against a reduced-round variant of AES. Anthropic emphasized that neither result affects production systems today. The significance is methodological: a frontier model performed cryptanalysis at a level the team compares to top human experts, mostly autonomously, and at a pace that compresses years of review into days.

HAWK: halving effective key strength in 60 hours

HAWK is among the remaining candidates in NIST's call for additional digital signatures designed to survive quantum computers. Despite surviving two rounds of expert human review over roughly two years, Mythos improved the best-known attack in about 60 hours — effectively cutting HAWK's effective key strength in half.

The attack exploits a previously unexploited symmetry — a nontrivial automorphism — in the lattice underlying HAWK. Anthropic estimates the discovery cost roughly $100,000 in API compute. Mythos agents ran literature review, mathematical reasoning, and verification pipelines in a multi-agent harness with access to Python and Sage.

Anthropic shared the finding with HAWK authors in June and coordinated public disclosure with NIST's mailing list alongside the July 28 release.

Abstract data stream visualization for advanced computing research

AES: the Möbius Bridge and a billion output tokens

The second result targets AES-128 with seven of ten rounds — a standard academic reduction used to stress-test ciphers without claiming a break of full AES. Mythos improved meet-in-the-middle attacks by developing a fingerprinting algorithm it called a "Möbius Bridge," reducing work by a factor of 256 in one stage and yielding overall speedups between 200× and 800×.

The discovery path is as instructive as the result. Early runs ended with Claude insisting improved cryptanalysis of AES was impossible. After explicit prompting that models "tend to think it is impossible to solve so they don't try," Mythos rewrote its agent harness and spent three days producing hundreds of millions of tokens across three substantive human prompts. Researchers then spent several hundred hours validating correctness.

Anthropic is releasing papers on both attacks, Claude's chain of thought for the AES insight, and CryptanalysisBench — a benchmark built with academics at ETH Zurich, Tel Aviv University, and the University of Haifa.

Medical research laboratory with technical equipment

Beyond the headline ciphers

The blog also previews additional preliminary work: a practical key-recovery attack on 13-round LEA runnable on a desktop in under an hour, and extensions on Serpent-128, Salsa20, Poseidon, and SHA-1 with more limited gains.

Anthropic's conclusion is explicit about the bottleneck shifting: as models produce novel cryptographic outputs autonomously, human researchers may become limited by verification capacity — the same triage problem cybersecurity already faces with vulnerability discovery.

Why this matters now

Cryptographic standardization has always relied on adversarial review. What changes is speed and scale. In roughly one year, Anthropic writes, models progressed from struggling with basic ciphers to finding flaws in designs that survived years of expert review.

The July 28 release is not a production emergency. It is a calibration event: frontier models can now contribute to the review pipeline that underpins TLS, banking, and post-quantum migration planning — if the field builds the benchmarks, disclosure norms, and verification labor to absorb what they find.

Sources

Newsletter

Get the dispatch

One field. One email when we publish. Privacy.