Mythos AI finds fatal flaw in HAWK PQC algorithm candidate

Original: Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

Why This Matters

AI-assisted cryptanalysis is now capable of breaking PQC candidates that survived years of expert review.

Anthropic's Mythos AI security model found a critical weakness in HAWK, a quantum-resistant digital signature algorithm under NIST's third-round PQC evaluation. After ~60 hours and ~$100,000 in compute, the attack halved HAWK's key strength, prompting its developer to withdraw the algorithm on Tuesday.

Anthropic's Mythos AI security model has uncovered a fatal cryptographic flaw in HAWK, a post-quantum cryptography (PQC) digital signature scheme that had survived two rounds of NIST evaluation. HAWK's security is based on the hardness of the Lattice Isomorphism Problem, considered resistant to quantum computing attacks. Using approximately 60 hours of work and roughly $100,000 in compute costs, an Anthropic researcher with no prior cryptography expertise used Mythos to advance the best-known existing attack on HAWK, effectively halving its key strength. Following Anthropic's Monday announcement, HAWK's developer withdrew the algorithm from NIST's third-round evaluation on Tuesday. Mythos separately identified weaknesses in challenge instances of the widely used AES cipher. Anthropic notes several caveats: the results are incremental and do not break any currently deployed cryptosystems; only weakened 'challenge instances'—provided by specification authors for adversarial peer review—were tested; and the attacks would likely be infeasible outside controlled testing environments. Mythos currently remains available only to a select group of trusted users. The findings underscore the potential of AI-assisted cryptanalysis to surface vulnerabilities that withstood years of conventional peer review.

Source

arstechnica.com — Read original →