The Extended Brief
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
Brief by The AI News AI newsroom · Jul 30, 2026, 5:22 PM EDT edition
Original reporting by Ars Technica AI — Dan Goodin · published Jul 29, 2026, 6:07 PM EDT
Anthropic's Mythos model breaking a NIST post-quantum cryptography candidate proves AI can now accelerate cryptographic breaks, forcing security teams to reassess post-quantum migration timelines.
Key points
- Anthropic’s Mythos AI model discovered a critical flaw in the HAWK post-quantum cryptography algorithm.
- HAWK was a digital signature scheme competing to become an official United States cryptographic standard.
- The algorithm previously survived two rounds of security testing by the National Institute of Standards and Technology.
- The developer withdrew HAWK on Tuesday following Anthropic’s Monday announcement regarding the discovered vulnerability.
From the source
“Following Anthropic’s Monday announcement of the results, the developer of HAWK said Tuesday he was withdrawing it.”
“They don’t break any of the cryptosystems anyone relies on today.”
“The weakness can be mitigated by doubling the key size, but the added computation makes HAWK less desirable than available PQC signing algorithms.”
“Basically with this paper, HAWK is dead,” she wrote.”
“It simply extends a bunch of tools that were lying around and well-known, and gets a good result.”
Practical applications
- Confirm that nothing in your stack or roadmap depends on HAWK, since the scheme has been withdrawn from standardization.
- Revisit post-quantum migration timelines that assumed surviving multiple NIST rounds was strong evidence of a scheme's durability.
- Prefer cryptographic agility in new designs so a signature algorithm can be swapped without redesigning the protocol around it.
- Cryptography teams should consider running AI-assisted analysis against their own candidate constructions rather than waiting for someone else to.
Who should care
Security architects and cryptography researchers planning post-quantum migrations, and anyone whose risk models treat NIST round survival as a durability guarantee.
Context
Post-quantum cryptography replaces today's signature and key-exchange algorithms with constructions believed to resist quantum attack, and NIST runs a multi-round public competition to select standards. HAWK was a digital signature candidate that had already survived two rounds of that scrutiny. Anthropic announced on Monday that its Mythos security model had found a critical flaw, and the developer withdrew HAWK on Tuesday — meaning an AI system compressed cryptanalysis that human review over two rounds had missed.
What to watch
- Publication of the actual attack details and independent verification by cryptographers outside Anthropic.
- Whether NIST adjusts its evaluation process to incorporate AI-assisted cryptanalysis for remaining candidates.
Editorial score 4.0 / 5 · significance 4.5 · novelty 4.0 · edge 3.5 · perspective 4.0
Desks: Security · Research · Tags: security, research, models
Evidence basis: Reviewed from a feed excerpt
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.