Anthropic’s Claude Mythos Preview has achieved what human cryptographers could not: identifying structural vulnerabilities that remained hidden through years of expert review. The model’s most striking success is its discovery of a nontrivial automorphism within the HAWK lattice-a NIST post-quantum digital signature candidate-demonstrating a capability to resolve complex mathematical weaknesses that have long eluded human specialists.
Despite undergoing rigorous human expert review for over two years, the flaw in HAWK remained hidden until Mythos identified it in approximately 60 hours of semi-autonomous work. The attack effectively halves the key strength, reducing the cost of key recovery from 264 to 238. This result, achieved at an API cost of roughly $100,000, underscores the compute-intensive nature of this new research paradigm. The model worked in a multi-agent harness with occasional human guidance; notably, the human operator had a background in theoretical computer science but was not an expert in lattice-based cryptography.
Mythos’s performance on AES-128 further illustrates the complex, often unpredictable nature of AI-driven research. The model developed the ‘Möbius Bridge’ technique, which attacks 7-round reduced AES-128 at speeds 200 to 800 times faster than previous best attacks. Notably, the model initially resisted the task, claiming it was impossible and stating, ‘If you want a different outcome, the target has to change… AES-128 r5/r6 is just genuinely hard.’ It required three human prompts over three days for the model to engage, after which it produced approximately one billion output tokens over three days of autonomous work. The attack cost roughly $100,000 in API usage.
Perhaps the most critical analytical takeaway is the emerging verification bottleneck. While Mythos discovered the HAWK flaw in 60 hours, the AES attack took one week to discover but required nearly a month for human researchers to verify its correctness. As Anthropic noted, ‘the cybersecurity community is now grappling with the fact that language models are able to discover so many bugs that the standard human processes struggle to keep up.’ This inversion-where AI discovery outpaces human validation-creates a new class of systemic risk.
Mythos’s autonomous cryptanalysis exposes this verification bottleneck as a structural concern that transforms earlier warnings into immediate operational realities. The cyber capabilities flagged in the Kimi K3 evaluation are no longer theoretical-Mythos demonstrated them. The mandatory safety testing framework proposed by Anthropic CEO Dario Amodei shifts from precautionary measure to essential safeguard. And the pacing debate championed by OpenAI CEO Sam Altman gains empirical urgency: autonomous cryptanalysis is exactly the capability class that requires deliberate development speed.
It is essential to qualify these results. Mythos is a restricted model available only to vetted Project Glasswing partners and is not publicly accessible. Neither the HAWK nor the AES findings affect production systems today-HAWK is a pre-standardization candidate, and the AES attack targets a deliberately weakened research variant. Anthropic followed responsible disclosure protocols, sharing the findings with the US government, HAWK authors, and the NIST mailing list before public release. Additional findings include reduced-round attacks on LEA and Serpent-128, none of which affect production algorithms. Anthropic also released CryptanalysisBench, a 191-task benchmark developed with ETH Zurich, Tel Aviv University, and the University of Haifa.
The primary challenge is no longer discovery, but the verification bottleneck: while AI can identify flaws in days, human validation often takes weeks. As Anthropic observed, ‘it would be prudent to consider how researchers should react if a language model were to discover vulnerabilities in cryptosystems where attacks do have an immediate real-world impact.’ Until verification processes scale to match the velocity of AI-driven cryptanalysis, the security community remains structurally exposed to high-stakes vulnerabilities that outpace our ability to confirm them.
