Anthropic AI Model Discovers New Weaknesses in Core Encryption Algorithms

The420.in Staff
4 Min Read

Anthropic has published research revealing that its unreleased artificial intelligence model, Claude Mythos Preview, discovered fundamental mathematical weaknesses in core encryption protocols that safeguard global internet traffic. The company released its findings on Tuesday across two technical research papers, detailing how the model successfully executed an attack against a reduced 7-round variant of AES-128. While standard 10-round AES implementations securing daily financial transfers, encrypted chats, Wi-Fi networks, and stored data remain uncompromised, the model’s new attack technique runs between 200 and 800 times faster than any previously recorded cryptanalytic method.

Beyond standard symmetric ciphers, the model demonstrated significant capabilities against post-quantum cryptography. Claude Mythos effectively halved the key strength of HAWK, an advanced signature scheme shortlisted for standardization by the US National Institute of Standards and Technology (NIST) that had previously survived two years of expert human evaluation.

Autonomous Problem-Solving and the Möbius Bridge Method

The discovery process highlighted novel reasoning behaviors in the underlying AI architecture. When researchers initially tasked Claude Mythos with searching for flaws in Advanced Encryption Standard (AES) protocols, the model declined the prompt, asserting that the block cipher had been exhaustively studied and no further mathematical improvements were possible.

To bypass this roadblock, researchers provided a deliberately flawed prompt encouraging the model to re-examine its internal assumptions. In response, Claude Mythos modified its own agent execution harness to systematically search for novel mathematical pathways. Working continuously over a 60-hour window, the model consumed roughly one billion tokens and expended approximately $100,000 in API compute costs across two main results.

The process yielded a new fingerprinting methodology named the “Möbius Bridge,” which removes one of the manual guesses an attacker previously needed to attempt. Following the autonomous generation of these proofs, two Anthropic researchers spent nearly a month verifying and confirming the mathematical validity of the model’s output.

Technical Implications for Cryptographic Standards

The findings present immediate challenges for next-generation security standards and legacy encryption algorithms alike. For the post-quantum candidate HAWK-256, the mathematical key recovery work factor dropped exponentially. Cryptographers note that doubling key sizes to offset this vulnerability strips away the core performance advantages that made the algorithm attractive for widespread deployment.

In addition to its findings on AES variants and HAWK, Anthropic flagged a working key-recovery attack against 13-round LEA that successfully retrieves full keys in under an hour using standard desktop hardware. The researchers also recorded incremental cryptanalytic progress against other widely used algorithms, including Serpent-128, Salsa20, and the SHA-1 hash function.

Safety Controls, Benchmarks, and Future Policy

Prior to public disclosure, Anthropic shared its research data directly with US government entities and key industry security partners. To establish standardized evaluation metrics for future model iterations, the company partnered with researchers at ETH Zurich, Tel Aviv University, and the University of Haifa to launch CryptanalysisBench, a public benchmark designed to track the growth rate of AI cryptanalytic capabilities.

Deployment of Claude Mythos remains tightly restricted following its initial April release, with access limited exclusively to select government agencies after early testing confirmed advanced capabilities in identifying and exploiting software vulnerabilities. Commenting on the long-term impact of AI-assisted cryptanalysis, former NSA general counsel Glenn Gerstell raised questions regarding whether long-standing security assumptions about the multi-year durability of strong encryption standards remain valid.

Stay Connected