AI found a weakness in one of the world's most studied encryption systems — is your data under threat?
No, AI hasn't cracked the encryption protecting your bank account. But experts say Anthropic's latest research could change how tomorrow's cryptography is tested.
Artificial intelligence (AI) has helped uncover new weaknesses in two cryptographic systems, including a simplified version of the Advanced Encryption Standard (AES) that underpins much of today's internet. While these headline-grabbing findings don't put anyone's passwords or bank accounts at immediate risk, experts say the research could mark the beginning of a new era in which AI becomes a powerful assistant for discovering flaws in the mathematical foundations of digital security.
In a blog post published July 28, representatives from Anthropic's Frontier Red Team said Claude Mythos Preview independently developed new cryptanalytic techniques against two different targets: a version of AES-128, one of the world's most widely used encryption algorithms, and HAWK, an experimental post-quantum digital signature scheme currently being evaluated as part of the U.S. National Institute of Standards and Technology's (NIST) effort to standardize cryptography for the quantum computing age.
It's tempting to interpret this news as AI cracking one of the internet's most important encryption algorithms, but the reality is less dramatic. Nonetheless, experts say the achievement could mark the start of a new age of digital security.
The power of encryption
AES protects huge amounts of everyday digital life, from encrypted websites and messaging apps to Wi-Fi networks and financial transactions. But the version Anthropic attacked wasn't the full AES-128 algorithm used in those systems. Instead, the researchers studied a seven-round version of AES, a deliberately weakened variant long used by cryptographers to test new attack techniques.
The full AES-128 algorithm uses 10 rounds of encryption, while Anthropic's research focused on a seven-round version. In a self-published study that has not been peer-reviewed, scientists Milad Nasr and Nicholas Carlini said Claude found a faster way to recover the encryption key from that simplified version, making the best-known attack between 200 and 800 times faster. However, the study stressed that the technique does not work against the full version of AES used to protect real-world systems.
The more significant result may instead involve HAWK. Unlike AES, which has protected data for more than two decades, HAWK is a relatively new digital signature scheme designed to resist attacks from future quantum computers. It's one of the remaining candidates in NIST's additional post-quantum signature standardization process, meaning it is still being scrutinized by researchers before its widespread deployment.
This development illustrates how AI can act as a powerful accelerator in cryptanalysis.
Thomas Espitau, head of research at PQShield
In a separate study, Anthropic scientists Zygimantas Straznickas and Stephen A. Weis found that Claude spotted a mathematical property that researchers hadn't previously exploited. Combined with existing attack techniques, this property made it much easier to recover HAWK's secret key.
Thomas Espitau — head of research at PQShield, a cybersecurity company that specializes in post-quantum cryptography, and a cryptographer who has published research on HAWK — described the work as "one of the most, if not the most significant, cryptanalytic result of the year."
"To say it plainly, this is great work, and it is exactly what the NIST process is designed to produce," Espitau told Live Science. "Candidate schemes exist to be attacked before they are deployed, not after."
Espitau said the attack combined previously known techniques with one missing mathematical insight that Claude identified, substantially reducing HAWK's estimated security margin. He believes the work demonstrates how AI could increasingly help researchers evaluate the strength of cryptographic systems before they are adopted.
"This development illustrates how AI can act as a powerful accelerator in cryptanalysis," he said. "Claude Mythos Preview identified the exploitation of the sign-flip symmetry, providing the final piece of a puzzle that the research community had been assembling."
Building defensive measures
However, not everyone thinks the announcement means AI suddenly outsmarted human cryptographers.
"There is nothing you need to change," Roberta Faux, head of cryptography at cybersecurity and quantum encryption company Arqit, told Live Science. "Both Anthropic and the outside cryptographers agree that you don't need to change your key sizes or switch your cryptography."
Instead, Faux said the bigger story is AI's ability to apply expert-level cryptanalysis across thousands of algorithms that relatively few researchers have had time to examine.
"The interesting prospect is not a model outdueling the world's best lattice theorist on one problem but a model applying solid, roughly expert-level analysis at scale to the several thousand ciphers nobody ever had the human-hours to examine," she said.
Related stories
Faux also cautioned against attributing the HAWK breakthrough solely to AI.
"The HAWK attack used no exotic ingredients; it simply competently assembled tools that were already lying around," she said. "A post-quantum candidate is seriously scrutinized by maybe a few dozen people on the planet, so beating two years of review mostly reveals how thin that layer of review is."
For consumers, the immediate implications are reassuring. The encryption protecting online banking, shopping, messaging and cloud storage has not suddenly become obsolete. But for the researchers designing the next generation of cryptography, Anthropic's work hints that AI could soon help cryptographers test tomorrow's encryption schemes more quickly and more thoroughly than has previously been possible.
Carly Page is a technology journalist and copywriter with more than a decade of experience covering cybersecurity, emerging tech, and digital policy. She previously served as the senior cybersecurity reporter at TechCrunch.
Now a freelancer, she writes news, analysis, interviews, and long-form features for publications including Forbes, IT Pro, LeadDev, Resilience Media, The Register, TechCrunch, TechFinitive, TechRadar, TES, The Telegraph, TIME, Uswitch, WIRED, and others. Carly also produces copywriting and editorial work for technology companies and events.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.