← Blog · · df00tech

Anthropic Says Claude AI Model Helped Derive New Attacks on HAWK-256 and 7-Round AES-128

security-news technique

What happened

According to Anthropic, as reported by The Hacker News, its Claude Mythos Preview model assisted researchers in deriving two cryptanalytic results: an end-to-end key-recovery attack against the post-quantum signature scheme HAWK-256, and a 200- to 800-fold speedup for an existing attack on seven-round AES-128.

The HAWK attack reportedly exploits a previously unused symmetry in the lattice structure underlying the signature scheme. Anthropic's released implementation is said to have an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server.

Why it matters for defenders

HAWK is a post-quantum signature candidate, so a practical key-recovery attack against HAWK-256 specifically is significant for organizations evaluating or piloting post-quantum cryptography migrations. The AES-128 result applies only to a reduced, seven-round variant of AES (full AES-128 uses ten rounds), so it is a cryptanalytic research milestone rather than a break of AES as deployed in production systems today. Both results are also notable as an example of AI-assisted cryptanalysis accelerating research that previously required manual mathematical derivation.

What defenders should watch for or do now

  • Track whether HAWK-256 is used in any post-quantum pilots, libraries, or vendor products in your environment, and monitor for updated guidance from NIST or the HAWK team in response to this disclosure.
  • Do not treat the seven-round AES-128 result as an operational break of AES-128 or AES-256 as used in TLS, disk encryption, or other production contexts — no full-round AES attack is reported here.
  • Watch for follow-up disclosures or patches from HAWK maintainers and cryptographic library vendors, and reassess if HAWK-256 is in your PQC roadmap.
  • More broadly, expect AI-assisted cryptanalysis to shorten the time between novel research techniques and practical attacks, and factor that into how quickly your organization deprecates aging or experimental cryptographic schemes.

Developing story

This is net-new intelligence and details may evolve as Anthropic, the HAWK team, and the broader cryptographic community respond. For the original report, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.