Return to Threats

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

thehackernews.com 2026-07-29 AI supply chain High

What Happened

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Why It Matters

Report facts: Anthropic’s Claude Mythos Preview was used as an autonomous cryptanalysis agent to discover a practical end-to-end key-recovery attack on the HAWK-256 post-quantum signature test parameter and a 200–800x speedup for attacking seven-round AES-128, exploiting a previously unused lattice symmetry in HAWK and delivering a working implementation that runs in hours on a 96-core server[1][4][6][8]. Anthropic and independent coverage emphasize that these are research-level attacks on test or round-reduced schemes and do not directly impact current production cryptosystems, though HAWK is under active NIST standardization review[1][4][6][8]. RealGround analysis: The article illustrates that advanced AI models can function as high-powered cryptanalytic components in the broader security supply chain, rapidly uncovering mathematical weaknesses in candidate algorithms that had passed years of human review, which in turn could cascade into standards changes and downstream software updates[4][6][7][8]. Organizations relying on emerging cryptographic standards or AI-augmented security tooling need structured AI supply chain governance: tracking which models and agents participate in

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html

Talk to AI CISO